First published: Wed Oct 09 2024(Updated: )
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik Reporting | <10.2.24.924 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8015 is classified as a critical vulnerability due to its potential for remote code execution.
To remediate CVE-2024-8015, upgrade to Progress Telerik Report Server version 2024 Q3 (10.2.24.924) or later.
CVE-2024-8015 allows attackers to perform remote code execution through object injection, potentially compromising the entire server.
Versions of Progress Telerik Report Server prior to 2024 Q3 (10.2.24.924) are affected by CVE-2024-8015.
Yes, CVE-2024-8015 can be exploited remotely, making it particularly dangerous for unpatched servers.