PT-2024-22785 · Devolutions · Devolutions Server
Published
2024-04-09
·
Updated
2025-03-28
·
CVE-2024-2918
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Server versions 2024.1.6 and earlier
Description
The issue is related to improper input validation in the PAM JIT elevation feature, allowing an attacker with access to this feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.
Recommendations
For Devolutions Server versions 2024.1.6 and earlier, consider restricting access to the PAM JIT elevation feature until a fix is available.
As a temporary workaround, avoid using the PAM JIT elevation checkout request feature in Devolutions Server until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devolutions Server