CVE-2025-8353

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

06 Aug 2025, 14:37

Type Values Removed Values Added
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
First Time Devolutions
Devolutions devolutions Server
References () https://devolutions.net/security/advisories/DEVO-2025-0013/ - () https://devolutions.net/security/advisories/DEVO-2025-0013/ - Vendor Advisory

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) El problema de sincronización de la interfaz de usuario en la interfaz de aprobación de solicitudes de acceso Just-in-Time (JIT) en Devolutions Server 2025.2.4.0 y versiones anteriores permite que un atacante autenticado remoto obtenga acceso no autorizado a grupos JIT eliminados a través de un estado de interfaz de usuario obsoleto durante el procesamiento de solicitudes de pago estándar.

30 Jul 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

30 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-30 16:15

Updated : 2025-08-06 14:37


NVD link : CVE-2025-8353

Mitre link : CVE-2025-8353

CVE.ORG link : CVE-2025-8353


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-446

UI Discrepancy for Security Feature