Security & Compliance
DEVO-2024-0015
Summary
Devolutions Server is affected by a vulnerability.
Affected Products
Devolutions Server 2024.3.6 and earlier
Change Log
2024-11-12 - - Initial publication
Severity
High
Product
Devolutions Server
Fix Version
DVLS 2024.3.7
Improper access control in the Password History
Description
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
Remediation and Workarounds
Upgrade to DVLS 2024.3.7.0 or higher
Severity
5.3 medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
DVLS 2024.3.6 and earlier
CVE(s)
CVE-2024-10971