CVE-2025-0332

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telerik:ui_for_winforms:*:*:*:*:*:*:*:*

History

21 Feb 2025, 12:03

Type Values Removed Values Added
CPE cpe:2.3:a:telerik:ui_for_winforms:*:*:*:*:*:*:*:*
References () https://docs.telerik.com/devtools/winforms/knowledge-base/kb-security-path-traversal-cve-2025-0332 - () https://docs.telerik.com/devtools/winforms/knowledge-base/kb-security-path-traversal-cve-2025-0332 - Vendor Advisory
Summary
  • (es) En Progress® Telerik® UI for WinForms, versiones anteriores a 2025 Q1 (2025.1.211), el uso de una limitación incorrecta de una ruta de destino puede provocar la descompresión del contenido de un archivo en un directorio restringido.
First Time Telerik
Telerik ui For Winforms

12 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 16:15

Updated : 2025-02-21 12:03


NVD link : CVE-2025-0332

Mitre link : CVE-2025-0332

CVE.ORG link : CVE-2025-0332


JSON object : View

Products Affected

telerik

  • ui_for_winforms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')