Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.
This issue affects the following versions :
Devolutions Server 2025.2.15.0 and earlier
| Software | From | Fixed in |
|---|---|---|
| devolutions / devolutions_server | - | 2025.2.17.0 |
| devolutions / devolutions_server | 2025.3.2.0 | 2025.3.6.0 |