CVE-2024-1856: Progress Telerik Reporting Remote Deserialization Vulnerability
Published Mar 20, 2024
·Updated
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
Affected Software
1 affected component
Progress Telerik Reporting<18.0.24.130
Event History
Mar 20, 2024
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1856?
The severity of CVE-2024-1856 is considered high due to its potential for remote code execution.
2
How do I fix CVE-2024-1856?
To fix CVE-2024-1856, update Telerik Reporting to version 18.0.24.130 or later.
3
What software versions are affected by CVE-2024-1856?
CVE-2024-1856 affects all versions of Progress Telerik Reporting prior to 2024 Q1 (18.0.24.130).
4
Can CVE-2024-1856 be exploited remotely?
Yes, CVE-2024-1856 can be exploited remotely by a threat actor due to an insecure deserialization vulnerability.
5
What are the potential consequences of CVE-2024-1856 exploitation?
Exploitation of CVE-2024-1856 can lead to unauthorized code execution on the affected system.