Improper privilege assignment in PAM JIT privilege sets in Devolutions
Server allows a PAM user to perform PAM JIT
requests on unauthorized groups by exploiting a user interface issue.
This issue affects the following versions :
* Devolutions Server 2025.1.3.0 through 2025.1.7.0
* Devolutions Server 2024.3.15.0 and earlier
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0008/ |
![]() ![]() |
History
Wed, 25 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Devolutions
Devolutions devolutions Server |
|
CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Devolutions
Devolutions devolutions Server |
Wed, 28 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 28 May 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier | |
Weaknesses | CWE-266 | |
References |
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-05-28T12:35:36.654Z
Updated: 2025-05-28T14:01:58.786Z
Reserved: 2025-05-09T12:08:57.852Z
Link: CVE-2025-4493

Updated: 2025-05-28T14:01:55.387Z

Status : Analyzed
Published: 2025-05-28T13:15:19.817
Modified: 2025-06-25T15:48:22.483
Link: CVE-2025-4493

No data.