Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier
History

Wed, 25 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions devolutions Server
CPEs cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Vendors & Products Devolutions
Devolutions devolutions Server

Wed, 28 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 May 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier
Weaknesses CWE-266
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2025-05-28T12:35:36.654Z

Updated: 2025-05-28T14:01:58.786Z

Reserved: 2025-05-09T12:08:57.852Z

Link: CVE-2025-4493

cve-icon Vulnrichment

Updated: 2025-05-28T14:01:55.387Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-28T13:15:19.817

Modified: 2025-06-25T15:48:22.483

Link: CVE-2025-4493

cve-icon Redhat

No data.