CVE-2024-1801: Progress Telerik Reporting Local Deserialization Vulnerability
Published Mar 20, 2024
·Updated
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
Affected Software
1 affected component
Progress Telerik Reporting<18.0.24.130
Event History
Mar 20, 2024
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1801?
CVE-2024-1801 has a high severity rating due to its potential for code execution by a local threat actor.
2
How do I fix CVE-2024-1801?
To fix CVE-2024-1801, update Progress® Telerik® Reporting to version 2024 Q1 (18.0.24.130) or later.
3
Who is affected by CVE-2024-1801?
CVE-2024-1801 affects all versions of Progress® Telerik® Reporting prior to 2024 Q1 (18.0.24.130).
4
What type of vulnerability is CVE-2024-1801?
CVE-2024-1801 is classified as an insecure deserialization vulnerability.
5
Can CVE-2024-1801 be exploited remotely?
No, CVE-2024-1801 requires a local threat actor to exploit the vulnerability.