First published: Mon Jul 19 2021(Updated: )
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sheetjs Sheetjs | <=0.16.9 | |
Sheetjs Sheetjs Pro | <=0.16.9 | |
Oracle REST Data Services | <21.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SheetJS and SheetJS Pro vulnerability is CVE-2021-32014.
The severity of CVE-2021-32014 is medium with a severity value of 5.5.
CVE-2021-32014 allows attackers to cause a denial of service (CPU consumption) through a crafted .xlsx document when read by xlsx.js in SheetJS and SheetJS Pro versions up to 0.16.9.
To fix CVE-2021-32014 in SheetJS and SheetJS Pro, users should update to a version later than 0.16.9.
More information about CVE-2021-32014 can be found at the following references: [Link 1](https://floqast.com/engineering-blog/post/fuzzing-and-parsing-securely/), [Link 2](https://sheetjs.com/pro), [Link 3](https://www.npmjs.com/package/xlsx/v/0.17.0).