First published: Mon Jul 19 2021(Updated: )
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sheetjs Project Sheetjs | <=0.16.9 | |
Sheetjs Project Sheetjs Pro | <=0.16.9 | |
Oracle REST Data Services | <21.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32013 is a vulnerability in SheetJS and SheetJS Pro through version 0.16.9 that allows attackers to cause a denial of service by consuming excessive memory.
CVE-2021-32013 affects SheetJS and SheetJS Pro versions up to 0.16.9.
CVE-2021-32013 is classified as a medium severity vulnerability.
The CWE-ID of CVE-2021-32013 is 400 (Uncontrolled Resource Consumption)
Yes, you can find more information about CVE-2021-32013 in the following references: [1](https://floqast.com/engineering-blog/post/fuzzing-and-parsing-securely/), [2](https://sheetjs.com/pro), [3](https://www.npmjs.com/package/xlsx/v/0.17.0)