Incorrect Authorization in Permission Validation Component Leads to Reporting Endpoint Access
CVE-2024-12148

Currently unrated

Key Information:

Status
Vendor
CVE Published:
4 December 2024

What is CVE-2024-12148?

Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

Affected Version(s)

Server 0 <= 2024.3.6.0

References

Timeline

  • Vulnerability published

.