First published: Wed May 15 2024(Updated: )
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik Report Server | <10.1.24.514 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4357 is classified as an information disclosure vulnerability.
To fix CVE-2024-4357, upgrade to Progress Telerik Report Server version 2024 Q1 (10.1.24.514) or later.
CVE-2024-4357 affects users of Progress Telerik Report Server version 2024 Q1 (10.0.24.305) or earlier.
CVE-2024-4357 enables low-privilege attackers to read sensitive system files.
XML External Entity Processing is a technique exploited in CVE-2024-4357 that allows unauthorized access to system files.