CVE-2024-2915

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

27 Mar 2025, 19:32

Type Values Removed Values Added
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
First Time Devolutions
Devolutions devolutions Server
References () https://devolutions.net/security/advisories/DEVO-2024-0005 - () https://devolutions.net/security/advisories/DEVO-2024-0005 - Vendor Advisory

26 Mar 2024, 17:09

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 16:15

Updated : 2025-03-27 19:32


NVD link : CVE-2024-2915

Mitre link : CVE-2024-2915


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE

No CWE.