CVE-2024-4358

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telerik:report_server_2024:*:*:*:*:*:*:*:*

History

14 Jun 2024, 17:59

Type Values Removed Values Added
CWE CWE-290
First Time Telerik report Server 2024
Telerik
CPE cpe:2.3:a:telerik:report_server_2024:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - Mitigation, Vendor Advisory

29 May 2024, 15:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-29 15:16

Updated : 2025-01-27 21:43


NVD link : CVE-2024-4358

Mitre link : CVE-2024-4358


JSON object : View

Products Affected

telerik

  • report_server_2024
CWE
CWE-290

Authentication Bypass by Spoofing