CVE Vulnerabilities

CVE-2024-6096

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Published: Jul 24, 2024 | Modified: Jul 26, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In ProgressĀ® TelerikĀ® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Weakness

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Affected Software

Name Vendor Start Version End Version
Telerik_reporting Progress * 18.1.24.709 (excluding)

Potential Mitigations

References