Service interruption or command injection via prototype pollution
Published Feb 12, 2025 · Updated Feb 12, 2025
Prototype pollution in KendoReact 3.5.0 through 9.3.1 allows remote authenticated users to interrupt service or inject commands. The Form component lets attacker-controlled property names introduce or change global prototype-chain properties; Progress has not disclosed the exact affected function or assignment path. Exposure requires the Form component, and Progress has not published the input route or application-specific authorization needed to reach it.
Summary
What happened
Prototype pollution in KendoReact 3.5.0 through 9.3.1 allows remote authenticated users to interrupt service or inject commands. The Form component lets attacker-controlled property names introduce or change global prototype-chain properties; Progress has not disclosed the exact affected function or assignment path. Exposure requires the Form component, and Progress has not published the input route or application-specific authorization needed to reach it.
The record
- CVE
- CVE-2024-12629
- Published
- Feb 12, 2025
- Updated
- Feb 12, 2025
- Vendor
- Progress Software Corporation
- Product
- KendoReact
- Classifications
- CWE-1321, CAPEC-248, CAPEC-469, T1499, T1059
- Attack vector
- network
- Privileges
- admin
Timeline
How it unfolded
- Feb 12, 2025CVE publishedPublication date reported by the CVE source.
- Feb 12, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.5.0 <9.4.0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo