Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.
History

Fri, 02 May 2025 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-270

Fri, 02 May 2025 12:45:00 +0000

Type Values Removed Values Added
Description Privilege context switching error in PAM JIT feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM JIT account password to be improperly reset after usage via specific actions such as editing the username. Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.
Weaknesses CWE-266

Thu, 01 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 May 2025 18:45:00 +0000

Type Values Removed Values Added
Description Privilege context switching error in PAM JIT feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM JIT account password to be improperly reset after usage via specific actions such as editing the username.
Weaknesses CWE-270
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2025-05-01T18:26:22.565Z

Updated: 2025-05-02T12:21:00.974Z

Reserved: 2025-04-11T13:27:07.314Z

Link: CVE-2025-3517

cve-icon Vulnrichment

Updated: 2025-05-01T18:47:02.381Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-01T19:15:58.517

Modified: 2025-05-02T13:52:51.693

Link: CVE-2025-3517

cve-icon Redhat

No data.