Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.
References
Link | Resource |
---|---|
https://devolutions.net/security/advisories/DEVO-2024-0017 | Vendor Advisory |
Configurations
History
28 Mar 2025, 16:22
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
References | () https://devolutions.net/security/advisories/DEVO-2024-0017 - Vendor Advisory | |
Summary |
|
|
First Time |
Devolutions devolutions Server
Devolutions |
Information
Published : 2024-12-04 18:15
Updated : 2025-03-28 16:22
NVD link : CVE-2024-12196
Mitre link : CVE-2024-12196
CVE.ORG link : CVE-2024-12196
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-863
Incorrect Authorization