← Back

CVE-2024-12196

nvd nist
Published: Dec 4, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.

Affected (1)

1 product
Devolutions Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2024.3.8.0

References (1)

Source: security@devolutions.net
Vendor Advisory

Timeline

No history available yet.