First published: Mon Jul 19 2021(Updated: )
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sheetjs Project Sheetjs | <=0.16.9 | |
Sheetjs Project Sheetjs Pro | <=0.16.9 | |
Oracle REST Data Services | <21.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-32012.
The severity of CVE-2021-32012 is medium with a CVSS score of 5.5.
SheetJS and SheetJS Pro versions up to and including 0.16.9 are affected by CVE-2021-32012.
An attacker can exploit CVE-2021-32012 by crafting a malicious .xlsx document that is mishandled when read by xlsx.js.
Yes, an updated version of SheetJS (0.17.0) is available to fix CVE-2021-32012.