From 66800ae7b8c559a67981604820b7ae6c9e0f767e Mon Sep 17 00:00:00 2001 From: Dess <dyordano@progress.com> Date: Wed, 12 Feb 2025 18:10:20 +0200 Subject: [PATCH 1/2] Update kb-security-path-traversal-cve-2024-11343.md --- knowledge-base/kb-security-path-traversal-cve-2024-11343.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/knowledge-base/kb-security-path-traversal-cve-2024-11343.md b/knowledge-base/kb-security-path-traversal-cve-2024-11343.md index bbd63b4c..e94aad61 100644 --- a/knowledge-base/kb-security-path-traversal-cve-2024-11343.md +++ b/knowledge-base/kb-security-path-traversal-cve-2024-11343.md @@ -38,6 +38,6 @@ All customers who have a Telerik license can access the downloads here [Product [CVE-2024-11343](https://www.cve.org/CVERecord?id=CVE-2024-11343) (HIGH) -**CVSS:** 7.3 +**CVSS:** 8.3 -In Progress® Telerik® Document Processing, versions prior to 2025 Q1 (2025.1.2xx), improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. \ No newline at end of file +In Progress® Telerik® Document Processing, versions prior to 2025 Q1 (2025.1.2xx), improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. From a50996d4d823df00fe4f07df3df89eaad7b57365 Mon Sep 17 00:00:00 2001 From: Desislava Yordanova <dyordano@progress.com> Date: Wed, 12 Feb 2025 18:12:09 +0200 Subject: [PATCH 2/2] Update kb-security-rtf-filecontent-export-cve-2024-11629.md --- .../kb-security-rtf-filecontent-export-cve-2024-11629.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/knowledge-base/kb-security-rtf-filecontent-export-cve-2024-11629.md b/knowledge-base/kb-security-rtf-filecontent-export-cve-2024-11629.md index e71068e1..2229414b 100644 --- a/knowledge-base/kb-security-rtf-filecontent-export-cve-2024-11629.md +++ b/knowledge-base/kb-security-rtf-filecontent-export-cve-2024-11629.md @@ -38,6 +38,6 @@ All customers who have a Telerik license can access the downloads here [Product [CVE-2024-11629](https://www.cve.org/CVERecord?id=CVE-2024-11629) (HIGH) -**CVSS:** 7.3 +**CVSS:** 7.1 In Progress Telerik Document Processing Libraries, versions prior to 2025 Q1 (2025.1.2xx), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. \ No newline at end of file