CVE-2021-23921
https://notcve.org/view.php?id=CVE-2021-23921
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements. Se detectó un problema en Devolutions Server versiones anteriores a 2020.3. Se presenta un control de acceso roto en los elementos de entrada de la Lista de Contraseñas. • https://devolutions.net/security/advisories/devo-2021-0002 •
CVE-2021-23923
https://notcve.org/view.php?id=CVE-2021-23923
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users. Se detectó un problema en Devolutions Server versiones anteriores a 2020.3. Se presenta una autenticación rota con los usuarios del dominio de Windows. • https://devolutions.net/security/advisories/devo-2021-0002 • CWE-287: Improper Authentication •
CVE-2021-28047
https://notcve.org/view.php?id=CVE-2021-28047
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields. Cross-Site Scripting (XSS) en Administrative Reports en Devolutions Remote Desktop Manager versiones anteriores a 2021.1, permite a los usuarios autenticados remotamente inyectar scripts web o HTML arbitrarios a través de múltiples campos de entrada. • https://devolutions.net/security/advisories/devo-2021-0003 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-36211
https://notcve.org/view.php?id=CVE-2020-36211
An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur. Se detectó un problema en la crate gfwx versiones anteriores a 0.3.0 para Rust. Debido a que ImageChunkMut no posee límites en su atributo Send o Sync, una carrera de datos y corrupción de la memoria puede ocurrir • https://rustsec.org/advisories/RUSTSEC-2020-0104.html • CWE-662: Improper Synchronization CWE-787: Out-of-bounds Write •