Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2024-0007
Devolutions Server is affected by a vulnerability.
Affected Products
Change Log
17/5/2024 - Initial publication
Medium 6.0 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Improper input validation in PAM JIT elevation feature allows LDAP injection
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
Affected Products
CVE(s)
CVE-2024-5072
Remediation and Workarounds
Upgrade to Devolutions Server 2024.1.12.0 or higher




