Описание
SheetJS Regular Expression Denial of Service (ReDoS)
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package xlsx are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.
Пакеты
Наименование
xlsx
npm
Затронутые версииВерсия исправления
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
почти 2 года назад
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).