ej2-base Vulnerability issue

While running fortify scan on Angualr Solution containing Syncfusion controls, we are receiving below error.

Image_4502_1700138141744

We are using following ej2-base version 20.4.51. Let us know if you require any other information in order to resolve this issue. Also, there is suggestion where scan is suggesting to use non-vulnerable version. since, we are not sure if latest version will fix this issue. can you confirm if this has been handled in latest version


Image_5995_1700138717100




2 Replies

PD PDev November 21, 2023 12:08 PM UTC

Any update on this issue ? 



TJ Theveshwar Jayakumar Syncfusion Team November 30, 2023 02:27 AM UTC

Hi Parth.Rawal,

 

Thank you for reaching out to Syncfusion support.


We understand that you are facing vulnerability issue in your application with fortify scan.
Based on the details currently we are investigating the following scenario from our end, and we need some additional time to further investigate this issue. Meanwhile, to evaluate further we would like to gather the following details, which will help us provide a prompt solution:

 

  1. The Syncfusion controls used in your application other than ej2-base file.
  2. The versions of the packages used in the application.
  3. If possible, please share the complete package.json file.
     

Providing the above details will enable us to offer a prompt solution from our end.

 

Regards,

Theveshwar


Loader.
Up arrow icon