Sécurité et conformité
DEVO-2024-0015
Résumé
Devolutions Server is affected by a vulnerability.
Produits affectés
Devolutions Server 2024.3.6 and earlier
Journal des modifications
2024-11-12 - - Initial publication
Sévérité
High
Produit
Devolutions Server
Version corrigée
DVLS 2024.3.7
Improper access control in the Password History
Description
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
Mesures correctives et solutions de contournement
Upgrade to DVLS 2024.3.7.0 or higher
Sévérité
5.3 medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produits affectés
DVLS 2024.3.6 and earlier
CVE(s)
CVE-2024-10971