CVE-2021-32013: Medium severity sheetjs vulnerability
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-32013?
CVE-2021-32013 is a vulnerability in SheetJS and SheetJS Pro through version 0.16.9 that allows attackers to cause a denial of service by consuming excessive memory.
How does CVE-2021-32013 affect SheetJS and SheetJS Pro?
CVE-2021-32013 affects SheetJS and SheetJS Pro versions up to 0.16.9.
What type of vulnerability is CVE-2021-32013?
CVE-2021-32013 is classified as a medium severity vulnerability.
What is the CWE-ID of CVE-2021-32013?
The CWE-ID of CVE-2021-32013 is 400 (Uncontrolled Resource Consumption)
Are there any references available for CVE-2021-32013?
Yes, you can find more information about CVE-2021-32013 in the following references: [1](https://floqast.com/engineering-blog/post/fuzzing-and-parsing-securely/), [2](https://sheetjs.com/pro), [3](https://www.npmjs.com/package/xlsx/v/0.17.0)