CVE-2024-7295: Hard-coded credentials used for temporary and cache data encryption
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7295?
CVE-2024-7295 is considered a high severity vulnerability due to the risk of sensitive data exposure.
How do I fix CVE-2024-7295?
To fix CVE-2024-7295, upgrade Progress Telerik Report Server to version 2024 Q4 (10.3.24.1112) or later.
What does CVE-2024-7295 exploit?
CVE-2024-7295 exploits the use of an outdated encryption algorithm for local asset data in previous Telerik Report Server versions.
Who is affected by CVE-2024-7295?
Organizations using Progress Telerik Report Server versions prior to 2024 Q4 (10.3.24.1112) are affected by CVE-2024-7295.
What kind of data is at risk in CVE-2024-7295?
CVE-2024-7295 puts local asset data at risk of being decrypted by sophisticated attackers.