CVE-2024-7294: Uncontrolled resource consumption of anonymous endpoints
Published Oct 9, 2024
·Updated
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
Affected Software
1 affected component
Progress Telerik Reporting<10.2.24.806
Event History
Oct 9, 2024
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7294?
CVE-2024-7294 is categorized as a denial-of-service vulnerability due to its ability to allow HTTP DoS attacks on anonymous endpoints.
2
Which versions of Telerik Report Server are affected by CVE-2024-7294?
CVE-2024-7294 affects all versions of Telerik Report Server prior to 2024 Q3 (10.2.24.806).
3
How do I fix CVE-2024-7294?
To mitigate CVE-2024-7294, you should upgrade to Telerik Report Server version 2024 Q3 (10.2.24.806) or later.
4
What type of attacks can exploit CVE-2024-7294?
CVE-2024-7294 can be exploited through HTTP denial-of-service attacks targeting anonymous endpoints.
5
Is there a workaround for CVE-2024-7294 before upgrading?
Currently, there are no documented workarounds for CVE-2024-7294, and upgrading is the recommended course of action.