Prototype Pollution in Progress® Telerik® Kendo UI for Vue
CVE-2024-11628

4.1MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2025

Summary

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

Affected Version(s)

Progress® Telerik® Kendo UI for Vue 2.4.0 < 6.1.0

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tariq Hawis
.