Devolutions Server 2024.3.8.0

CPE Details

Devolutions Server 2024.3.8.0
2024.3.8.0
2025-04-04
16h34 +00:00
2025-04-04
16h34 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:devolutions:devolutions_server:2024.3.8.0:*:*:*:*:*:*:*

Informations

Vendor

devolutions

Product

devolutions_server

Version

2024.3.8.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-2278 2025-03-13 12h56 +00:00 Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.
6.5
Medium
CVE-2025-2277 2025-03-13 12h47 +00:00 Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
7.5
High
CVE-2025-2003 2025-03-05 18h56 +00:00 Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
7.1
High
CVE-2025-1231 2025-02-11 14h05 +00:00 Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.
5.4
Medium
CVE-2024-12151 2024-12-04 17h17 +00:00 Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.
5
Medium