Incorrect privilege assignment in PAM JIT elevation...
Moderate severity
Unreviewed
Published
May 2, 2025
to the GitHub Advisory Database
•
Updated May 2, 2025
Description
Published by the National Vulnerability Database
May 1, 2025
Published to the GitHub Advisory Database
May 2, 2025
Last updated
May 2, 2025
Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.
References