In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
History

Thu, 20 Feb 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Telerik
Telerik kendoreact
CPEs cpe:2.3:a:telerik:kendoreact:*:*:*:*:*:*:*:*
Vendors & Products Telerik
Telerik kendoreact

Wed, 12 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Title Prototype Pollution in Progress® Telerik® KendoReact
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2025-02-12T15:55:43.633Z

Reserved: 2024-12-13T18:49:19.322Z

Link: CVE-2024-12629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-02-12T16:15:39.810

Modified: 2025-02-20T20:40:12.200

Link: CVE-2024-12629

cve-icon Redhat

No data.