CVE-2021-28048
14.04.2021, 20:15
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.Enginsight
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2020.3.18 |
| devolutions | devolutions_server | 𝑥 < 2021.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration