CVE-2024-5072: Input Validation
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5072?
CVE-2024-5072 is rated as a high severity vulnerability due to improper input validation in the PAM JIT elevation feature.
How do I fix CVE-2024-5072?
To fix CVE-2024-5072, update to Devolutions Server version 2024.1.11.1 or later.
Who is affected by CVE-2024-5072?
CVE-2024-5072 affects authenticated users of Devolutions Server version 2024.1.11.0 and earlier who can access the PAM JIT elevation feature.
What type of vulnerability is CVE-2024-5072?
CVE-2024-5072 is categorized as an input validation vulnerability.
Can CVE-2024-5072 lead to unauthorized access?
Yes, CVE-2024-5072 can allow authenticated users to manipulate LDAP query filters, potentially leading to unauthorized access.