CVE-2024-12196
—CVSS 3.1
6.5 medium
EPSS
<1%p38
Published
()
Modified
Description
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.
- Vendors
- devolutions
- Products
- devolutions server
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.