PT-2021-6996 · Xlsx.Js+2 · Xlsx.Js+2

Published

2021-07-19

·

Updated

2022-02-28

·

CVE-2021-32014

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SheetJS versions through 0.16.9 SheetJS Pro versions through 0.16.9
Description The issue is related to an uncontrolled resource consumption in SheetJS and SheetJS Pro. Exploitation of this issue may allow an attacker to cause a denial of service via a specially crafted .xlsx document that is mishandled when read by xlsx.js, leading to CPU consumption.
Recommendations For SheetJS versions through 0.16.9, update to a version later than 0.16.9 to resolve the issue. For SheetJS Pro versions through 0.16.9, update to a version later than 0.16.9 to resolve the issue. As a temporary workaround, consider restricting the handling of .xlsx documents by xlsx.js until a patch is available.

Fix

Resource Exhaustion

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02832
CVE-2021-32014
GHSA-G973-978J-2C3P

Affected Products

Sheetjs
Sheetjs Pro
Xlsx.Js