praetorian-inc / chariot-ui

Chariot Offensive Security Platform
https://preview.chariot.praetorian.com
MIT License
15 stars 6 forks source link

CISA KEV Alert: Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability (CVE-2024-4358) #35

Closed UNC1739 closed 3 weeks ago

UNC1739 commented 3 weeks ago

CVE ID: CVE-2024-4358 Vendor/Project: Progress Product: Telerik Report Server Vulnerability Name: Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability Date Added: 2024-06-13 Short Description: Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access. Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Due Date: 2024-07-04 Known Ransomware Use: Unknown Notes: https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358

UNC1739 commented 3 weeks ago

I've confirmed that there is a nuclei template to detect this particular vulnerability.