Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions.
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2022-0008 | Vendor Advisory |
Configurations
Information
Published : 2022-11-01 12:15
Updated : 2022-11-03 10:16
NVD link : CVE-2022-3780
Mitre link : CVE-2022-3780
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
devolutions
- remote_desktop_manager