CVE-2024-12629

In ProgressĀ® TelerikĀ® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:kendoreact:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-12 16:15

Updated : 2025-06-27 17:24


NVD link : CVE-2024-12629

Mitre link : CVE-2024-12629

CVE.ORG link : CVE-2024-12629


JSON object : View

Products Affected

progress

  • kendoreact
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')