CVE-2024-11628

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:*

History

21 Feb 2025, 12:08

Type Values Removed Values Added
References () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - Vendor Advisory
Summary
  • (es) En Progress® Telerik® Kendo UI para Vue versiones v2.4.0 a v6.0.1, un atacante puede introducir o modificar propiedades dentro de la cadena de prototipos global, lo que puede resultar en una denegación de servicio o inyección de comandos.
First Time Telerik
Telerik kendo Ui For Vue
CPE cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:*

12 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 17:15

Updated : 2025-02-21 12:08


NVD link : CVE-2024-11628

Mitre link : CVE-2024-11628

CVE.ORG link : CVE-2024-11628


JSON object : View

Products Affected

telerik

  • kendo_ui_for_vue
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')