CVE-2024-12148
4.3MEDIUMIncorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.
Published: 12/4/2024Updated: 3/28/2025
Description
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.
AI AnalysisPowered by AI
Affected Products
devolutionsdevolutions_server
References
- https://devolutions.net/security/advisories/DEVO-2024-0017Vendor Advisory