PT-2024-7990 · Telerik · Telerik Report Server

Markus Wulftange

·

Published

2024-09-10

·

Updated

2024-10-15

·

CVE-2024-8015

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telerik Report Server versions prior to 2024 Q3 (10.2.24.924)
Description The issue is related to an insecure type resolution vulnerability, allowing a remote code execution attack through object injection. This vulnerability can be exploited by providing input that enables the selection of classes, potentially leading to arbitrary code execution.
Recommendations For versions prior to 2024 Q3 (10.2.24.924), update to version 2024 Q3 (10.2.24.924) or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable component until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-09504
CVE-2024-8015

Affected Products

Telerik Report Server