CVE-2021-32012: Medium severity sheetjs vulnerability
Published Jul 19, 2021
·Updated
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
Affected Software
3 affected components
Sheetjs Project Sheetjs Node.js<=0.16.9
Sheetjs Project Sheetjs Pro Node.js<=0.16.9
Oracle REST Data Services<21.2.4
Remediation
Patch Available
Event History
Jul 19, 2021
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-32012.
2
What is the severity of CVE-2021-32012?
The severity of CVE-2021-32012 is medium with a CVSS score of 5.5.
3
What software is affected by CVE-2021-32012?
SheetJS and SheetJS Pro versions up to and including 0.16.9 are affected by CVE-2021-32012.
4
How can an attacker exploit CVE-2021-32012?
An attacker can exploit CVE-2021-32012 by crafting a malicious .xlsx document that is mishandled when read by xlsx.js.
5
Is there a fix for CVE-2021-32012?
Yes, an updated version of SheetJS (0.17.0) is available to fix CVE-2021-32012.