CVE-2024-12148: Medium severity devolutions server vulnerability
Published Dec 4, 2024
·Updated
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.
Affected Software
2 affected components
Devolutions Server<=2024.3.6.0
Devolutions Devolutions Server<2024.3.7.0
Event History
Dec 4, 2024
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12148?
CVE-2024-12148 is classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive reporting endpoints.
2
How do I fix CVE-2024-12148?
To fix CVE-2024-12148, upgrade Devolutions Server to version 2024.3.6.1 or later.
3
Who is affected by CVE-2024-12148?
CVE-2024-12148 affects Devolutions Server versions up to and including 2024.3.6.0.
4
What type of vulnerability is CVE-2024-12148?
CVE-2024-12148 is an incorrect authorization vulnerability in the permission validation component.
5
Can CVE-2024-12148 be exploited by unauthenticated users?
No, CVE-2024-12148 requires an authenticated user to exploit the vulnerability.