Security Advisories in ASP.NET MVC DOCX Editor
27 Aug 20261 minute to read
Syncfusion® prioritizes the security of its controls. You can rely on the security of our controls, as we have implemented all necessary measures to mitigate security vulnerabilities such as cross-site scripting and insecure dependencies. To meet security standards, Syncfusion® uses the ESLint and ESLint plugin security tools for static code analysis. Additionally, Syncfusion® packages are scanned using the SOOS security tool.
This document describes the security updates available for Syncfusion® Essential® JS2 controls for each volume release.
Security Updates
The following security updates are available for the Syncfusion® DOCX Editor and are listed by release version.
2024 Volume 2 (v26.2.4) - July 25, 2024
This release resolves critical and moderate security vulnerabilities affecting the Syncfusion® DOCX Editor Docker image.
Threat:
-
ASP.NET Core (Kestrel) Components: Multiple moderate vulnerabilities in HTTP request handling could lead to access control issues and data leakage.
-
Npgsql: A potential SQL injection vulnerability via Protocol Message Size Overflow was detected.
-
Dynamic LINQ: Vulnerable to remote code execution via untrusted input manipulation.
Resolution:
-
Updated the affected ASP.NET Core packages.
-
The Npgsql package and Dynamic LINQ have been removed because they are no longer required. This change enhances security and mitigates the risk of SQL injection attacks.
Common Security Updates
For details on common security updates related to Syncfusion® products, see this link. This resource provides information on the latest advisories and best practices to help ensure the security and integrity of your applications.
Security Issue
If you discover a security issue with Syncfusion® controls or need help resolving it, contact us by creating a support ticket on our support site or by posting your query on Stack Overflow with the tag syncfusion-ej2.