CVE-2024-4358

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telerik:report_server_2024:*:*:*:*:*:*:*:*

History

21 Oct 2025, 23:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4358 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4358', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:20

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4358 -

21 Nov 2024, 09:42

Type Values Removed Values Added
References () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - Mitigation, Vendor Advisory () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - Mitigation, Vendor Advisory

14 Jun 2024, 17:59

Type Values Removed Values Added
References () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - () https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:telerik:report_server_2024:*:*:*:*:*:*:*:*
First Time Telerik
Telerik report Server 2024

14 Jun 2024, 01:00

Type Values Removed Values Added
Summary
  • (es) En Progress Telerik Report Server, versión 2024 Q1 (10.0.24.305) o anterior, en IIS, un atacante no autenticado puede obtener acceso a la funcionalidad restringida de Telerik Report Server a través de una vulnerabilidad de omisión de autenticación.

29 May 2024, 15:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-29 15:16

Updated : 2025-10-21 23:16


NVD link : CVE-2024-4358

Mitre link : CVE-2024-4358

CVE.ORG link : CVE-2024-4358


JSON object : View

Products Affected

telerik

  • report_server_2024
CWE
CWE-290

Authentication Bypass by Spoofing