Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365.
The user will stay authenticated until the Devolutions Server token expiration.
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2024-0002 | Vendor Advisory |
https://devolutions.net/security/advisories/DEVO-2024-0002 | Vendor Advisory |
Configurations
History
28 Mar 2025, 16:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://devolutions.net/security/advisories/DEVO-2024-0002 - Vendor Advisory | |
CWE | CWE-613 | |
First Time |
Devolutions devolutions Server
Devolutions |
|
CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* |
21 Nov 2024, 08:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://devolutions.net/security/advisories/DEVO-2024-0002 - |
01 Nov 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
06 Mar 2024, 15:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
05 Mar 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-05 22:15
Updated : 2025-03-28 16:21
NVD link : CVE-2024-1900
Mitre link : CVE-2024-1900
CVE.ORG link : CVE-2024-1900
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-613
Insufficient Session Expiration