PT-2024-38774 · Progress · Telerik Document Processing Libraries

Published

2024-11-13

·

Updated

2024-11-18

·

CVE-2024-8049

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Progress Telerik Document Processing Libraries versions prior to 2024 Q4 (2024.4.1106)
Description: The issue arises when importing a document with unsupported features, leading to excessive processing and excessive use of computing resources. This results in the application process becoming unavailable due to resource exhaustion.
Recommendations: For versions prior to 2024 Q4 (2024.4.1106), update to version 2024.4.1106 or later to resolve the issue. As a temporary workaround, consider restricting the import of documents with unsupported features to minimize the risk of excessive processing and resource exhaustion.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-8049

Affected Products

Telerik Document Processing Libraries