CVE-2024-12629

MEDIUM

Progress Kendoreact < 9.4.0 - Prototype Pollution

Title source: rule
STIX 2.1

Description

In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

Scores

CVSS v3 4.1
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (1)
progress/kendoreact 3.5.0 - 9.4.0
Published Feb 12, 2025
Tracked Since Feb 18, 2026