CVE-2024-4202: Progress Telerik Reporting Local Instantiation Vulnerability
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Reportingto a version that resolves this vulnerability.Fixed in 2024 Q2 (18.1.24.514)
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4202?
CVE-2024-4202 is categorized as a critical vulnerability due to the potential for code execution.
How do I fix CVE-2024-4202?
To remediate CVE-2024-4202, upgrade to Progress Telerik Reporting version 2024 Q2 (18.1.24.514) or later.
What versions of Telerik Reporting are affected by CVE-2024-4202?
CVE-2024-4202 affects all versions of Progress Telerik Reporting prior to version 2024 Q2 (18.1.24.514).
What type of attack does CVE-2024-4202 allow?
CVE-2024-4202 allows for a code execution attack due to an insecure instantiation vulnerability.
Is there a workaround for CVE-2024-4202?
There are no official workarounds for CVE-2024-4202; upgrading to a fixed version is strongly recommended.