CVE-2024-11628
Description
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
CWE
- CWE-1321 — CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Affected
- Progress Software / Progress® Telerik® Kendo UI for Vue — v=2.4.0 <6.1.0 [affected]
CVSS
- 3.1 score=4.1 severity=MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
References
- https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 vendor-advisory
Source
cvelistV5-main/cves/2024/11xxx/CVE-2024-11628.json