CVE-2024-11628

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:kendo_ui_for_vue:*:*:*:*:*:*:*:*

History

27 Jun 2025, 19:18

Type Values Removed Values Added
First Time Progress
Progress kendo Ui For Vue
CPE cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:* cpe:2.3:a:progress:kendo_ui_for_vue:*:*:*:*:*:*:*:*

21 Feb 2025, 12:08

Type Values Removed Values Added
CPE cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:*
First Time Telerik kendo Ui For Vue
Telerik
References () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - () https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628 - Vendor Advisory
Summary
  • (es) En Progress® Telerik® Kendo UI para Vue versiones v2.4.0 a v6.0.1, un atacante puede introducir o modificar propiedades dentro de la cadena de prototipos global, lo que puede resultar en una denegación de servicio o inyección de comandos.

12 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 17:15

Updated : 2025-06-27 19:18


NVD link : CVE-2024-11628

Mitre link : CVE-2024-11628

CVE.ORG link : CVE-2024-11628


JSON object : View

Products Affected

progress

  • kendo_ui_for_vue
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')