CVE-2024-10971: Infoleak
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10971?
CVE-2024-10971 has been classified with a severity rating that indicates a significant risk due to improper access control affecting sensitive data.
How do I fix CVE-2024-10971?
To fix CVE-2024-10971, update Devolutions DVLS to version 2024.3.7 or later where access controls have been properly implemented.
Who is affected by CVE-2024-10971?
CVE-2024-10971 affects users of Devolutions DVLS version 2024.3.6 and earlier.
What type of vulnerability is CVE-2024-10971?
CVE-2024-10971 is an access control vulnerability that allows authenticated users to access sensitive data improperly.
Could CVE-2024-10971 lead to data exposure?
Yes, CVE-2024-10971 can lead to unauthorized access and exposure of sensitive data by malicious authenticated users.