First published: Wed Oct 09 2024(Updated: )
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik Reporting | <10.2.24.806 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7294 is categorized as a denial-of-service vulnerability due to its ability to allow HTTP DoS attacks on anonymous endpoints.
CVE-2024-7294 affects all versions of Telerik Report Server prior to 2024 Q3 (10.2.24.806).
To mitigate CVE-2024-7294, you should upgrade to Telerik Report Server version 2024 Q3 (10.2.24.806) or later.
CVE-2024-7294 can be exploited through HTTP denial-of-service attacks targeting anonymous endpoints.
Currently, there are no documented workarounds for CVE-2024-7294, and upgrading is the recommended course of action.