PT-2023-4424 · Unknown · Sheetjs Community Edition

Stof

·

Publicado

2023-04-12

·

Atualizado

2025-10-31

·

CVE-2023-30533

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SheetJS Community Edition versions prior to 0.19.3
Description The issue is related to a Prototype Pollution vulnerability, which can be exploited by a remote attacker using a specially crafted file, potentially allowing for unauthorized actions. The SheetJS Community Edition receives over 2 million weekly downloads, and versions prior to 0.19.3 are affected. Workflows that do not read arbitrary files are unaffected.
Recommendations For versions prior to 0.19.3, consider avoiding the use of the affected functionality until a fixed version is available. As a temporary workaround, restrict the reading of arbitrary files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04769
CVE-2023-30533
GHSA-4R6H-8V6P-XVW6

Produtos afetados

Sheetjs Community Edition