Prototype Pollution in Progress® Telerik® Kendo UI for Vue
CVE-2024-11628
4.1MEDIUM
Key Information:
- Vendor
- Progress Software
- Vendor
- CVE Published:
- 12 February 2025
Summary
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Affected Version(s)
Progress® Telerik® Kendo UI for Vue 2.4.0 < 6.1.0
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tariq Hawis