vendor:
Telerik Report Server
by:
VeryLazyTech
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Telerik Report Server
Affected Version From: 2024 Q1 (10.0.24.305)
Affected Version To: Earlier versions
Patch Exists: NO
Related CWE: CVE-2024-4358
CPE: a:telerik:report_server:10.0.24.305
Platforms Tested: Windows Server 2019
2024
Progress Telerik Report Server 2024 Q1 (10.0.24.305) – Authentication Bypass
The Progress Telerik Report Server 2024 Q1 version 10.0.24.305 and earlier allows attackers to bypass authentication. This vulnerability has been assigned CVE-2024-4358.
Mitigation:
To mitigate this issue, it is recommended to update the Progress Telerik Report Server to a patched version that addresses the authentication bypass vulnerability.