Progress discloses second critical flaw in Telerik Report Server in as many months
ID: 8cb6a361-259d-58ff-9d12-137a90eb9525
STIX ID: report--8cb6a361-259d-58ff-9d12-137a90eb9525
Feed Name: The Register (Security)
Threat Score
Progress/Telerik disclosed multiple severe vulnerabilities in Telerik Report Server and Reporting—CVE-2024-6327 (insecure deserialization, CVSS 9.9) enabling RCE on affected versions and CVE-2024-6096 (unsafe type resolution, CVSS 8.8) also leading to potential RCE—with upgrades required to fixed versions; the advisory notes the real-world risk given past exploitation of a related deserialization bug by threat actors against US federal targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
