Security & Compliance
DEVO-2024-0015
Zusammenfassung
Devolutions Server is affected by a vulnerability.
Betroffene Produkte
Devolutions Server 2024.3.6 and earlier
Änderungsprotokoll
2024-11-12 - - Initial publication
Schweregrad
High
Produkt
Devolutions Server
Behobene Version
DVLS 2024.3.7
Improper access control in the Password History
Beschreibung
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
Behebungen und Workarounds
Upgrade to DVLS 2024.3.7.0 or higher
Schweregrad
5.3 medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Betroffene Produkte
DVLS 2024.3.6 and earlier
CVE(s)
CVE-2024-10971