CVE-2024-1800: Progress Telerik Report Server Deserialization
Published Mar 20, 2024
·Updated
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.
Affected Software
1 affected component
Progress Telerik Report Server<10.0.24.130
Event History
Mar 20, 2024
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Jun 3, 2024
News Published
via BleepingComputer·05:58 PM
News Published
via BleepingComputer·06:00 PM
Jul 25, 2024
News Published
via BleepingComputer·03:46 PM
Jul 26, 2024
News Published
via The Register·01:32 PM
News Published
via The Register·01:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-1800?
CVE-2024-1800 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-1800?
To fix CVE-2024-1800, upgrade your Progress Telerik Report Server to version 10.0.24.130 or later.
3
What impact does CVE-2024-1800 have on affected systems?
CVE-2024-1800 can allow unauthorized users to execute arbitrary code on vulnerable systems.
4
Which versions of Telerik Report Server are affected by CVE-2024-1800?
CVE-2024-1800 affects all versions of Progress Telerik Report Server prior to 2024 Q1 (10.0.24.130).
5
Is there a workaround for CVE-2024-1800 until a fix is applied?
There are no reliable workarounds for CVE-2024-1800; the recommended solution is to upgrade to the patched version.