Access Control Flaw in Devolutions Server Web Extension
CVE-2025-2280

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
13 March 2025

What is CVE-2025-2280?

A flaw in the web extension restriction feature of Devolutions Server versions 2024.3.13 and earlier permits authenticated users to bypass essential browser extension restrictions, potentially compromising the security of user data and system integrity. This issue necessitates prompt attention and remediation to ensure user access controls are effectively enforced.

Affected Version(s)

Server 0 <= 2024.3.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.