CVE-2024-5072

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

28 Mar 2025, 16:22

Type Values Removed Values Added
First Time Devolutions devolutions Server
Devolutions
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://devolutions.net/security/advisories/DEVO-2024-0007 - () https://devolutions.net/security/advisories/DEVO-2024-0007 - Vendor Advisory

21 Nov 2024, 09:46

Type Values Removed Values Added
References () https://devolutions.net/security/advisories/DEVO-2024-0007 - () https://devolutions.net/security/advisories/DEVO-2024-0007 -

19 Nov 2024, 22:35

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en la función de elevación PAM JIT en Devolutions Server 2024.1.11.0 y versiones anteriores permite que un usuario autenticado con acceso a la función de elevación PAM JIT manipule la consulta del filtro LDAP a través de una solicitud especialmente manipulada.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

17 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 16:15

Updated : 2025-03-28 16:22


NVD link : CVE-2024-5072

Mitre link : CVE-2024-5072

CVE.ORG link : CVE-2024-5072


JSON object : View

Products Affected

devolutions

  • devolutions_server