Telerik Report Server Product Security Update Advisory

Overview

 

An update has been released to address vulnerability in the Telerik Report Server product. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

Telerik Report Server 2024 Q1 (10.0.24.305) or below

 

Resolved Vulnerabilities

 

Vulnerability that allows unauthenticated attackers to access limited functionality in Telerik Report Server via an authentication bypass vulnerability (CVE-2024-4358)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability patches version.

Telerik Report Server 2024 Q2 (10.1.24.514) or at least

 

Referenced Sites

 

[1] CVE-2024-4358 Detail

Https:// nvd.nist.gov/vuln/detail/CVE-2024-4358

[2] Authentication Bypass Vulnerability

https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358#what-are-the-impacts