CVE-2025-8353
BaseFortify
Publication date: 2025-07-30
Last updated on: 2025-08-06
Assigner: Devolutions Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| devolutions | devolutions_server | From 2022.3.1.0 (inc) to 2022.3.10.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-446 | The user interface does not correctly enable or configure a security feature, but the interface provides feedback that causes the user to believe that the feature is in a secure state. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a UI synchronization issue in the Just-in-Time (JIT) access request approval interface of Devolutions Server 2025.2.4.0 and earlier. It allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups by exploiting stale UI state during the standard checkout request processing.
How can this vulnerability impact me? :
The vulnerability can allow a remote authenticated attacker to access deleted JIT Groups without authorization, potentially leading to unauthorized access to sensitive systems or data that should no longer be accessible.