Progress Telerik Kendo UI for Vue
cpe:2.3:a:telerik:kendo_ui_for_vue:*:*:*:*:*:*:*
- >= 2.4.0, <= 6.0.1
A prototype pollution vulnerability has been identified in Progress Telerik Kendo UI for Vue, affecting versions 2.4.0 prior to 6.0.1. This vulnerability allows an attacker to introduce or modify properties within the global prototype chain, potentially leading to denial-of-service conditions or command injection.
Exploitation of this vulnerability can cause denial-of-service conditions or allow for command injection.
Users are advised to update to Kendo UI for Vue version 6.1.0 or later. The updated packages are available via npm. For more information, see the Kendo UI for Vue installation documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.