Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
| Software | From | Fixed in |
|---|---|---|
| devolutions / devolutions_server | - | 2023.2.8.0.x |