CVE-2018-15122: Input Validation
Published Aug 16, 2018
·Updated
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
Affected Software
2 affected components
Telerik JustAssembly>=2018.1.323.2
Telerik JustDecompile>=2018.2.605.0
Event History
Aug 16, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15122?
The severity of CVE-2018-15122 is high (7.8).
2
How does CVE-2018-15122 affect Telerik JustAssembly?
CVE-2018-15122 affects Telerik JustAssembly versions up to and including 2018.1.323.2.
3
How does CVE-2018-15122 affect Telerik JustDecompile?
CVE-2018-15122 affects Telerik JustDecompile versions up to and including 2018.2.605.0.
4
How can code be executed using CVE-2018-15122?
Code can be executed by decompiling a compiled .NET object with an embedded resource file and clicking on the resource.
5
Are there any known fixes or patches for CVE-2018-15122?
Yes, please refer to the following resources for information on fixes and patches: [link 1], [link 2].