Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
CVSS Information
N/A
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Devolutions Server 授权问题漏洞
Vulnerability Description
Devolutions Server是加拿大Devolutions公司的服务器设备。 Devolutions Server存在授权问题漏洞,该漏洞源于PAM SSH密钥和证书检索端点授权不当,可能导致已验证的低权限用户通过直接对象引用凭证标识符来泄露SSH密钥或证书PAM凭据的私钥。
CVSS Information
N/A
Vulnerability Type
N/A