PT-2024-38774 · Progress · Telerik Document Processing Libraries

CVE-2024-8049

·

Published

2024-11-13

·

Updated

2024-11-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Progress Telerik Document Processing Libraries versions prior to 2024 Q4 (2024.4.1106)
Description: The issue arises when importing a document with unsupported features, leading to excessive processing and excessive use of computing resources. This results in the application process becoming unavailable due to resource exhaustion.
Recommendations: For versions prior to 2024 Q4 (2024.4.1106), update to version 2024.4.1106 or later to resolve the issue. As a temporary workaround, consider restricting the import of documents with unsupported features to minimize the risk of excessive processing and resource exhaustion.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8049

Affected Products

Telerik Document Processing Libraries