PT-2024-37681 · Devolutions · Devolutions Server

Published

2024-09-25

·

Updated

2024-10-01

·

CVE-2024-6512

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2024.2.10 and earlier
Description The issue allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
Recommendations For Devolutions Server versions 2024.2.10 and earlier, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6512

Affected Products

Devolutions Server