Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gffr-g4h9-f8x5

Опубликовано: 28 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue.

This issue affects the following versions : 

  • Devolutions Server 2025.1.3.0 through 2025.1.7.0
  • Devolutions Server 2024.3.15.0 and earlier

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue.

This issue affects the following versions : 

  • Devolutions Server 2025.1.3.0 through 2025.1.7.0
  • Devolutions Server 2024.3.15.0 and earlier

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.5
nvd
9 месяцев назад

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266