Vulnerabilities > CVE-2024-1856 - Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-1801-cve-2024-1856
- https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-1801-cve-2024-1856
- https://www.telerik.com/products/reporting.aspx
- https://www.telerik.com/products/reporting.aspx