CVE-2021-32014

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
19/07/2021
Last modified:
28/02/2022

Description

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sheetjs:sheetjs:*:*:*:*:*:node.js:*:* 0.16.9 (including)
cpe:2.3:a:sheetjs:sheetjs_pro:*:*:*:*:*:node.js:*:* 0.16.9 (including)
cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:* 21.2.4 (excluding)