CVE-2024-11628

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:kendo_ui_for_vue:*:*:*:*:*:*:*:*

History

27 Jun 2025, 19:18

Type Values Removed Values Added
CPE cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:* cpe:2.3:a:progress:kendo_ui_for_vue:*:*:*:*:*:*:*:*
First Time Progress
Progress kendo Ui For Vue

21 Feb 2025, 12:08

Type Values Removed Values Added
References () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - Vendor Advisory
First Time Telerik kendo Ui For Vue
Telerik
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:*

12 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 17:15

Updated : 2025-06-27 19:18


NVD link : CVE-2024-11628

Mitre link : CVE-2024-11628


JSON object : View

Products Affected

progress

  • kendo_ui_for_vue
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')