CVE-2024-12629

In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telerik:kendoreact:*:*:*:*:*:*:*:*

History

20 Feb 2025, 20:40

Type Values Removed Values Added
First Time Telerik kendoreact
Telerik
CPE cpe:2.3:a:telerik:kendoreact:*:*:*:*:*:*:*:*
Summary
  • (es) En las versiones v3.5.0 a v9.4.0 de Progress® Telerik® KendoReact, un atacante puede introducir o modificar propiedades dentro de la cadena de prototipos global, lo que puede resultar en una denegación de servicio o una inyección de comandos.
References () https://www.telerik.com/kendo-react-ui/components/knowledge-base/kb-security-protoype-pollution-2024-12629 - () https://www.telerik.com/kendo-react-ui/components/knowledge-base/kb-security-protoype-pollution-2024-12629 - Vendor Advisory

12 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 16:15

Updated : 2025-02-20 20:40


NVD link : CVE-2024-12629

Mitre link : CVE-2024-12629

CVE.ORG link : CVE-2024-12629


JSON object : View

Products Affected

telerik

  • kendoreact
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')