Skip to content

Commit 2eb3998

Browse files
committed
kb(dpl-security): address DPL cve-2024-11343 vulnerability
1 parent 56102ce commit 2eb3998

File tree

1 file changed

+52
-0
lines changed

1 file changed

+52
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
---
2+
title: Address Telerik Document Processing Security Vulnerability
3+
description: Learn more about a fixed security vulnerability in Telerik Document Processing
4+
type: troubleshooting
5+
page_title: How to upgrade Telerik Document Processing to resove a security vulnerability
6+
slug: dpl-kb-security-vulnerability
7+
tags: blazor, dpl
8+
ticketid:
9+
res_type: kb
10+
---
11+
12+
## Environment
13+
14+
<table>
15+
<tbody>
16+
<tr>
17+
<td>Product</td>
18+
<td>Telerik Document Processing</td>
19+
</tr>
20+
<tr>
21+
<td>Version</td>
22+
<td>Prior to 2025.1.205</td>
23+
</tr>
24+
</tbody>
25+
</table>
26+
27+
## Description
28+
29+
The [February 2025 release of Telerik Document Processing](https://docs.telerik.com/devtools/document-processing/release-notes/2025/release-notes-2025-1-205) resolves a Path traversal vulnerability:
30+
31+
* [CVE-2024-11343](https://docs.telerik.com/devtools/document-processing/knowledge-base/kb-security-path-traversal-cve-2024-11343)
32+
33+
>tip Telerik UI for ASP.NET AJAX uses [Telerik Document Processing](https://docs.telerik.com/devtools/document-processing/introduction) packages and APIs for its Excel export features. **Telerik UI for ASP.NET AJAX is NOT affected by the mentioned resolved vulnerability.** This article exists only as a heads-up to customers who may be using Telerik Document Processing in their Telerik ASP.NET AJAX (Web Forms) applications.
34+
35+
This article describes potential next steps for developers working specifically with Telerik Document Processing.
36+
37+
## Solution
38+
39+
No action is required if:
40+
41+
* Your application is not referencing Telerik Document Processing packages explicitly.
42+
* Your application is not using `Telerik.Zip` APIs directly.
43+
44+
If your use case scenario is the opposite of the listed items above, then:
45+
46+
* [Get familiar with the vulnerabilities, their impact, and resolutions](#description).
47+
* Upgrade Telerik Document Processing to version **2025.1.205** or later.
48+
49+
## See Also
50+
51+
* [Release Notes for Telerik Document Processing version 2025.1.205 (2025 Q1)](https://docs.telerik.com/devtools/document-processing/release-notes/2025/release-notes-2025-1-205)
52+
* [KB article for CVE-2024-11343](https://docs.telerik.com/devtools/document-processing/knowledge-base/kb-security-path-traversal-cve-2024-11343)

0 commit comments

Comments
 (0)