Vulnerability Description
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Telerik Reporting | < 10.1.24.514 |
Related Weaknesses (CWE)
References
- https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024Vendor Advisory
- https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024Vendor Advisory
FAQ
What is CVE-2024-4357?
CVE-2024-4357 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity P...
How severe is CVE-2024-4357?
CVE-2024-4357 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4357?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Telerik Reporting.