CVE-2024-2915

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

27 Mar 2025, 19:32

Type Values Removed Values Added
First Time Devolutions devolutions Server
Devolutions
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
References () https://devolutions.net/security/advisories/DEVO-2024-0005 - () https://devolutions.net/security/advisories/DEVO-2024-0005 - Vendor Advisory

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://devolutions.net/security/advisories/DEVO-2024-0005 - () https://devolutions.net/security/advisories/DEVO-2024-0005 -

28 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-284 CWE-863

06 Aug 2024, 16:35

Type Values Removed Values Added
Summary
  • (es) El control de acceso inadecuado en la elevación de PAM JIT en Devolutions Server 2024.1.6 y versiones anteriores permite que un atacante con acceso a la función de elevación de PAM JIT se eleve a grupos no autorizados mediante una solicitud especialmente manipulada.
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

26 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 16:15

Updated : 2025-03-27 19:32


NVD link : CVE-2024-2915

Mitre link : CVE-2024-2915

CVE.ORG link : CVE-2024-2915


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-863

Incorrect Authorization