HIGH
Telerik Reporting EntityDataSource Insecure Type Resolution
Published Oct 9, 2024
8.8
HIGHCVSS 3.1
EPSS 0.62%
Description
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
Affected products
-
- Version 18.2.24.806StatusaffectedConstraints<18.2.24.924
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software | Telerik Reporting | unaffected |
|
- < 18.2.24.924
-
- Version 18.2.24.806StatusaffectedConstraints<18.2.24.924
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software | Telerik Reporting | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://docs.telerik.com/reporting/knowledge-base/insecure-type-resolution-cve-2024-8014 vendor-advisoryVendor Advisory
- https://security.netapp.com/advisory/ntap-20250425-0004/
| Link | Providers | Tags |
|---|---|---|
| https://docs.telerik.com/reporting/knowledge-base/insecure-type-resolution-cve-2024-8014 | vendor-advisoryVendor Advisory | |
| https://security.netapp.com/advisory/ntap-20250425-0004/ |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Oct 9, 2024
Updated Nov 3, 2025
Reserved Aug 20, 2024
Link CVE-2024-8014
CISA Vulnrichment
Updated Oct 9, 2024