Telerik Report Server Product Security Update Advisory (CVE-2024-1800)

Overview

 

An update has been made available to address a vulnerability in Telerik Report Server. users of affected versions are advised to update to the latest version.

 

Affected Products

 

Telerik Report Server 2024 Q1 (10.0.24.130) (10.0.24.130) or below

 

Resolved Vulnerabilities

 

Remote code execution vulnerability due to an insecure deserialization vulnerability (CVE-2024-1800)

 

Vulnerability Patches

 

vulnerability Patches were made available in the March 20, 2024 update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

Telerik Report Server 2024 Q1 (10.0.24.305) or at least

 

Referenced Sites

 

[1] CVE-2024-1800 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-1800

[2] Insecure Deserialization Vulnerability

https://docs.telerik.com/report-server/knowledge-base/deserialization-vulnerability-cve-2024-1800