First published: Wed Nov 13 2024(Updated: )
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik Reporting | <10.3.24.1112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7295 is considered a high severity vulnerability due to the risk of sensitive data exposure.
To fix CVE-2024-7295, upgrade Progress Telerik Report Server to version 2024 Q4 (10.3.24.1112) or later.
CVE-2024-7295 exploits the use of an outdated encryption algorithm for local asset data in previous Telerik Report Server versions.
Organizations using Progress Telerik Report Server versions prior to 2024 Q4 (10.3.24.1112) are affected by CVE-2024-7295.
CVE-2024-7295 puts local asset data at risk of being decrypted by sophisticated attackers.