In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Telerik
Telerik kendo Ui For Vue |
|
CPEs | cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*:* | |
Vendors & Products |
Telerik
Telerik kendo Ui For Vue |
Wed, 12 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
Title | Prototype Pollution in Progress® Telerik® Kendo UI for Vue | |
Weaknesses | CWE-1321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2025-02-12T19:06:31.802Z
Reserved: 2024-11-22T16:53:24.915Z
Link: CVE-2024-11628

Updated: 2025-02-12T19:06:11.532Z

Status : Analyzed
Published: 2025-02-12T17:15:22.067
Modified: 2025-02-21T12:08:11.927
Link: CVE-2024-11628

No data.