Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier
2025-05-28T13:15:19.817
2025-06-25T15:48:22.483
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | devolutions | devolutions_server | ≤ 2024.3.15.0 | Yes |
| Application | devolutions | devolutions_server | ≤ 2025.1.7.0 | Yes |