Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 33.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 33.00 |
VPI 공식 vpi-v1 기준