PT-2025-6508 · Telerik · Kendo Ui

Tariq Hawis

·

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2024-11628

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions In Progress Telerik Kendo UI for Vue versions v2.4.0 through v6.0.1
Description The issue allows an attacker to introduce or modify properties within the global prototype chain, which can result in denial of service or command injection.
Recommendations For versions v2.4.0 through v6.0.1, update to a version outside of this range to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to sensitive properties within the global prototype chain until a patch is available.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-11628

Affected Products

Kendo Ui