CVE-2024-4358 - Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
项目:Progress
产品:Telerik Report Server
添加日期:2024-06-13到期日:2024-07-04最后更新:June 21, 2025
漏洞名称
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
描述
Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.
已知用于勒索软件活动吗?
Unknown
采集行动
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
其他说明
https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358
https://nvd.nist.gov/vuln/detail/CVE-2024-4358
相关新闻文章
Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)July 26, 2024
Critical Flaw in Telerik Report Server Poses Remote Code Execution RiskJuly 26, 2024
Progress warns of critical RCE bug in Telerik Report ServerJuly 25, 2024
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)June 4, 2024
Exploit for critical Progress Telerik auth bypass released, patch nowJune 3, 2024