Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0832

Опубликовано: 31 янв. 2024
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
EPSS Низкий

Описание

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:progress:telerik_reporting:*:*:*:*:*:*:*:*
Версия до 18.0.24.130 (исключая)

EPSS

Процентиль: 71%
0.00674
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
github
около 2 лет назад

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

EPSS

Процентиль: 71%
0.00674
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo