We are running Veracode scan and received several Medium or less errors. with version - 24.6
I know the threads have popped up before, but they were older versions. Thank you.
aspose.cells.dll
Insufficient Entropy
Use of Externally-Controlled Input to Select Classes or Code (‘Unsafe Reflection’)
Use of a Broken or Risky Cryptographic Algorithm
Use of Hard-coded Cryptographic Key
Improper Resource Shutdown or Release
aspose.email.dll
Improper Certificate Validation
Use of a Broken or Risky Cryptographic Algorithm
Use of Externally-Controlled Input to Select Classes or Code (‘Unsafe Reflection’)
Use of Hard-coded Cryptographic Key
Use of a Broken or Risky Cryptographic Algorithm
Insufficient Entropy
Insertion of Sensitive Information Into Sent Data
Improper Resource Shutdown or Release
aspose.imaging.dll
Insufficient Entropy
Use of Externally-Controlled Input to Select Classes or Code (‘Unsafe Reflection’)
Server-Side Request Forgery (SSRF)
Use of a Broken or Risky Cryptographic Algorithm
Generation of Error Message Containing Sensitive Information
Could you please provide more specific details about the issues you are encountering with the Veracode scan? For example, are you looking for guidance on how to resolve these errors, or are you seeking information about the security practices related to the Aspose products mentioned?
Regarding Aspose.Cells, we will evaluate your mentioned Veracode issues. We have opened the following new ticket(s) in our internal issue tracking system and will deliver their fixes according to the terms mentioned in Free Support Policies.
Issue ID(s): CELLSNET-56399
Once we have an update on it, we will let you know here.
Please allow us to investigate from Aspose.PDF perspective. An investigation task as PDFNET-57825 has been generated in our issue management system for the sake. We will analyze it and let you know as soon as ticket is resolved. Please be patient and spare us some time.
We are afraid that the earlier logged ticket has not been yet resolved. It will be prioritized on a first come first serve basis and as soon as we make some progress towards its resolution, we will inform you. Please be patient and spare us some time.
We apologize, but the situation is the same for the ticket logged for Aspose.Cells. There is no update at the moment. Once we have any new information available, we will share it with you.