In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress Software
Progress Software telerik Report Server |
|
| CPEs | cpe:2.3:a:progress_software:telerik_report_server:1.0.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Progress Software
Progress Software telerik Report Server |
|
| Metrics |
ssvc
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2024-05-29T14:51:21.612Z
Updated: 2025-07-30T01:37:02.653Z
Reserved: 2024-04-30T17:34:38.695Z
Link: CVE-2024-4358
Updated: 2024-08-01T20:40:46.999Z
Status : Analyzed
Published: 2024-05-29T15:16:06.477
Modified: 2025-01-27T21:43:05.630
Link: CVE-2024-4358
No data.