Improper privilege assignment in PAM JIT privilege sets in Devolutions
Server allows a PAM user to perform PAM JIT
requests on unauthorized groups by exploiting a user interface issue.
This issue affects the following versions :
* Devolutions Server 2025.1.3.0 through 2025.1.7.0
* Devolutions Server 2024.3.15.0 and earlier
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2025-0008/ |
|
History
Wed, 25 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions devolutions Server |
|
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions
Devolutions devolutions Server |
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 28 May 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier | |
| Weaknesses | CWE-266 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2025-05-28T12:35:36.654Z
Updated: 2025-05-28T14:01:58.786Z
Reserved: 2025-05-09T12:08:57.852Z
Link: CVE-2025-4493
Updated: 2025-05-28T14:01:55.387Z
Status : Analyzed
Published: 2025-05-28T13:15:19.817
Modified: 2025-06-25T15:48:22.483
Link: CVE-2025-4493
No data.