PT-2021-6996 · Xlsx.Js+2 · Xlsx.Js+2
Published
2021-07-19
·
Updated
2022-02-28
·
CVE-2021-32014
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SheetJS versions through 0.16.9
SheetJS Pro versions through 0.16.9
Description
The issue is related to an uncontrolled resource consumption in SheetJS and SheetJS Pro. Exploitation of this issue may allow an attacker to cause a denial of service via a specially crafted .xlsx document that is mishandled when read by xlsx.js, leading to CPU consumption.
Recommendations
For SheetJS versions through 0.16.9, update to a version later than 0.16.9 to resolve the issue.
For SheetJS Pro versions through 0.16.9, update to a version later than 0.16.9 to resolve the issue.
As a temporary workaround, consider restricting the handling of .xlsx documents by xlsx.js until a patch is available.
Fix
Resource Exhaustion
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sheetjs
Sheetjs Pro
Xlsx.Js