logo
Home/CVEs/CVE-2024-4358/

CVE-2024-4358 - Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

Project:Progress

Product:Telerik Report Server

Date Added:2024-06-13Due Date:2024-07-04

Vulnerability Name

Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

Description

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358

https://nvd.nist.gov/vuln/detail/CVE-2024-4358

Related News Articles

Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)July 26, 2024

Critical Flaw in Telerik Report Server Poses Remote Code Execution RiskJuly 26, 2024

Progress warns of critical RCE bug in Telerik Report ServerJuly 25, 2024

PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)June 4, 2024

Exploit for critical Progress Telerik auth bypass released, patch nowJune 4, 2024