CVE-2024-4358 - Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

项目:Progress

产品:Telerik Report Server

添加日期:2024-06-13到期日:2024-07-04最后更新:June 21, 2025

漏洞名称

Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

描述

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

已知用于勒索软件活动吗?

Unknown

采集行动

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

其他说明

https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358

https://nvd.nist.gov/vuln/detail/CVE-2024-4358

相关新闻文章

Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)July 26, 2024

Critical Flaw in Telerik Report Server Poses Remote Code Execution RiskJuly 26, 2024

Progress warns of critical RCE bug in Telerik Report ServerJuly 25, 2024

PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)June 4, 2024

Exploit for critical Progress Telerik auth bypass released, patch nowJune 3, 2024

相关 CWE