New to Telerik UI for ASP.NET CoreStart a free 30-day trial

Address Telerik Document Processing Security Vulnerability

Environment

ProductTelerik Document Processing
Product VersionPrior to 2025.1.205

Description

The February 2025 release of Telerik Document Processing resolves a couple of vulnerabilities:

The Telerik.Core.Export package consumes the Progress Telerik Document Processing Libraries, in which for versions prior to 2025 Q1 (2025.1.2xx), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

Telerik UI for ASP.NET Core is NOT affected by the mentioned resolved vulnerabilities. This article exists only as a heads-up to customers who may be using Telerik Document Processing and/or Telerik.Core.Export in their Telerik UI for ASP.NET Core applications.

Solution

No action is required if:

  • Your application is not referencing Telerik Document Processing packages explicitly, or the Telerik.Core.Export package.
  • Your application is not using Telerik.Zip APIs directly.
  • Your application is not importing an HTML file and exporting it to RTF format.

If your use case scenario is the opposite of the listed items above, then:

The issue has been addressed in the Progress Telerik Document Processing Libraries and the Progress Telerik team strongly recommends performing an upgrade of the Progress Telerik Document Processing Libraries following the guidelines in the two Knowledge Base articles linked in the Description section and of the Telerik.Core.Export package to version 2025 Q1 (2025.1.211) or later.

See Also

In this article
EnvironmentDescriptionSolutionSee Also
Not finding the help you need?
Contact Support