Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Progress Software Telerik Reporting Vulnerability #675

Merged
merged 72 commits into from
Apr 26, 2024
Merged
Changes from all commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
b4cc4c6
Cisco Expressway Advisory
CharlesRN Feb 8, 2024
dc0499c
Merge branch 'wagov:main' into main
CharlesRN Feb 8, 2024
bf55723
Format markdown files
actions-user Feb 8, 2024
5b0d597
Update 20240208003-Cisco-Expressway-Series-Cross_Site-Request-Forgery.md
DGovEnterprise Feb 8, 2024
b500177
Format markdown files
actions-user Feb 8, 2024
5b4db62
Merge branch 'wagov:main' into main
CharlesRN Feb 14, 2024
d000bdb
Adobe Releases Security Updates
CharlesRN Feb 14, 2024
fe78203
Format markdown files
actions-user Feb 14, 2024
f6d67fe
Adobe Releases Security Updates
CharlesRN Feb 15, 2024
851e942
Format markdown files
actions-user Feb 15, 2024
9b39189
Merge branch 'wagov:main' into main
CharlesRN Feb 20, 2024
941c330
Bricks WordPress Advisory
CharlesRN Feb 20, 2024
c4294f0
Format markdown files
actions-user Feb 20, 2024
8aed4f3
Bricks WordPress
CharlesRN Feb 21, 2024
375ff6e
Zyxel security advisory
CharlesRN Feb 21, 2024
579de31
Merge branch 'wagov:main' into main
CharlesRN Feb 21, 2024
a89e74c
Format markdown files
actions-user Feb 21, 2024
60dcab9
Merge branch 'main' into main
DGovEnterprise Feb 21, 2024
453110a
Merge branch 'wagov:main' into main
CharlesRN Feb 26, 2024
c258f14
Linux Kernel Code Execution Vulnerability
CharlesRN Feb 26, 2024
9a8fa3d
Format markdown files
actions-user Feb 26, 2024
5a917f7
Merge branch 'main' into main
DGovEnterprise Feb 26, 2024
21e4bd9
Merge branch 'wagov:main' into main
CharlesRN Mar 7, 2024
a8b170d
Merge branch 'wagov:main' into main
CharlesRN Mar 8, 2024
9531242
released a security advisory
CharlesRN Mar 8, 2024
4b9e88c
Format markdown files
actions-user Mar 8, 2024
31a3986
Update and rename 20240308004-Android-security-advisory.md to 2024030…
DGovEnterprise Mar 8, 2024
427a100
Merge branch 'main' into main
DGovEnterprise Mar 8, 2024
ca9643a
Merge branch 'wagov:main' into main
CharlesRN Mar 8, 2024
7f3dd1c
Android security advisory 20240308004
CharlesRN Mar 8, 2024
b0d5f97
Format markdown files
actions-user Mar 8, 2024
56b354e
Merge branch 'wagov:main' into main
CharlesRN Mar 18, 2024
accb400
Fortinet Critical SQLi Vulnerability in FortiClientEMS
CharlesRN Mar 18, 2024
0482ef7
Format markdown files
actions-user Mar 18, 2024
a63baed
Update 20240318003-Fortinet-Critical-SQLi-Vulnerability-in-FortiClien…
DGovEnterprise Mar 18, 2024
3c68cf3
Merge branch 'main' into main
DGovEnterprise Mar 18, 2024
666a928
Format markdown files
actions-user Mar 18, 2024
fbb468c
Merge branch 'main' into main
DGovEnterprise Mar 18, 2024
e4c18e8
Merge branch 'wagov:main' into main
CharlesRN Mar 26, 2024
56652af
Firefox Patches Critical Zero-Day Vulnerabilities
CharlesRN Mar 26, 2024
8b4288d
Format markdown files
actions-user Mar 26, 2024
ac8ecaa
Merge branch 'wagov:main' into main
CharlesRN Mar 27, 2024
841c1f8
Firefox Patches Critical Zero-Day Vulnerabilities - 20240327003
CharlesRN Mar 27, 2024
81255c1
Format markdown files
actions-user Mar 27, 2024
adb4f80
Update 20240327003-Firefox-Patches-Critical-Zero-Day-Vulnerabilities.md
DGovEnterprise Mar 27, 2024
0ec8b81
Delete docs/advisories/20240326002-Firefox-Patches-Critical-Zero-Day-…
DGovEnterprise Mar 27, 2024
7cb8f75
Merge branch 'main' into main
DGovEnterprise Mar 27, 2024
e5105e8
Format markdown files
actions-user Mar 27, 2024
b0a0888
Merge branch 'wagov:main' into main
CharlesRN Apr 2, 2024
6f602ae
Merge branch 'wagov:main' into main
CharlesRN Apr 2, 2024
7a947e1
Supply Chain Compromise Affecting XZ Utils Data Compression Library -…
CharlesRN Apr 2, 2024
63bea09
Format markdown files
actions-user Apr 2, 2024
6cc9a6e
Merge branch 'main' into main
DGovEnterprise Apr 2, 2024
ad331b8
Merge branch 'wagov:main' into main
CharlesRN Apr 8, 2024
84be618
Cisco Vulnerability in Small Business Routers
CharlesRN Apr 8, 2024
dff0206
Format markdown files
actions-user Apr 8, 2024
52e5d2a
Updated overview to include all Router series.
CharlesRN Apr 8, 2024
0be23a6
Merge branch 'wagov:main' into main
CharlesRN Apr 15, 2024
32cc157
Bitdefender Advisory
CharlesRN Apr 15, 2024
f019ab9
Format markdown files
actions-user Apr 15, 2024
ed8d977
Merge branch 'main' into main
DGovEnterprise Apr 15, 2024
d49104e
Merge branch 'wagov:main' into main
CharlesRN Apr 18, 2024
09e888e
TP-Link Archer Routers Advisory
CharlesRN Apr 18, 2024
c0a5f9e
Format markdown docs
CharlesRN Apr 18, 2024
97d0685
Update 20240418003-Botnets-Swarm-Exploited-in-TP-Link-Archer-Routers.md
DGovEnterprise Apr 18, 2024
a807791
Merge branch 'main' into main
DGovEnterprise Apr 18, 2024
23bb21f
HashiCorp security advisory
CharlesRN Apr 22, 2024
0402bbc
Merge branch 'wagov:main' into main
CharlesRN Apr 22, 2024
4f1bf2c
Format markdown docs
CharlesRN Apr 22, 2024
b2fe1fc
Merge branch 'wagov:main' into main
CharlesRN Apr 26, 2024
f1c20e3
Progress Software Telerik Reporting Vulnerability
CharlesRN Apr 26, 2024
7573ed6
Format markdown docs
CharlesRN Apr 26, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Progress Software Telerik Reporting ObjectReader Vulnerability - 20240426003

## Overview

Progress Telerik has released a security advisory to address insecure deserialization vulnerability in Telerik Reporting product. The specific flaw exists within the ObjectReader class. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

## What is vulnerable?

| Product Affected | CVE | Severity | CVSS |
| --------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------- | ---- |
| Telerik Reporting 2024 Q1 all versions before 18.0.24.130 | [CVE-2024-1856](https://nvd.nist.gov/vuln/detail/CVE-2024-1856), [cve-2024-1801](https://nvd.nist.gov/vuln/detail/cve-2024-1801) | **High** | 8.5 |

## What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *one month...* (refer [Patch Management](../guidelines/patch-management.md)):

## Additional References

- [ZDI-24-402 | Zero Day Initiative](https://www.zerodayinitiative.com/advisories/ZDI-24-402/ "https://www.zerodayinitiative.com/advisories/ZDI-24-402/")
- [Insecure Deserialization Vulnerability - Telerik Reporting](https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-1801-cve-2024-1856)