CVE-2024-4358 - Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Project:Progress
Product:Telerik Report Server
Date Added:2024-06-13Due Date:2024-07-04
Vulnerability Name
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Description
Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358
https://nvd.nist.gov/vuln/detail/CVE-2024-4358
Related News Articles
Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)July 26, 2024
Critical Flaw in Telerik Report Server Poses Remote Code Execution RiskJuly 26, 2024
Progress warns of critical RCE bug in Telerik Report ServerJuly 25, 2024
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)June 4, 2024
Exploit for critical Progress Telerik auth bypass released, patch nowJune 4, 2024