CVE-2024-6096: Unsafe Deserialization Vulnerability
Published Jul 24, 2024
·Updated
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.
Affected Software
1 affected component
Progress Telerik Reporting<18.1.24.709
Event History
Jul 24, 2024
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 26, 2024
News Published
via The Register·01:32 PM
News Published
via The Register·01:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-6096?
CVE-2024-6096 is classified as a critical vulnerability due to its potential for code execution attacks.
2
How do I fix CVE-2024-6096?
To remediate CVE-2024-6096, update Progress Telerik Reporting to version 18.1.24.709 or later.
3
What versions are affected by CVE-2024-6096?
CVE-2024-6096 affects all versions of Progress Telerik Reporting prior to 18.1.24.709.
4
What type of attack is associated with CVE-2024-6096?
CVE-2024-6096 is associated with a code execution attack enabled by an insecure type resolution vulnerability.
5
How can I verify if my software is vulnerable to CVE-2024-6096?
You can verify your software's vulnerability to CVE-2024-6096 by checking if it is running a version earlier than 18.1.24.709.