CVE-2021-32014 describes a denial-of-service vulnerability affecting SheetJS and SheetJS Pro versions through 0.16.9, including Oracle REST Data Services integrations. A crafted .xlsx document can cause high CPU consumption when processed by xlsx.js, leading to service disruption. Rated Medium severity (CVSS 5.5), this vulnerability requires user interaction (UI:R) to open the malicious file, with a local attack vector (AV:L) and low attack complexity (AC:L). The primary impact is high availability loss (A:H), with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.16.9CPE matchmatch criteria | cpe:2.3:a:sheetjs:sheetjs:*:*:*:*:*:node.js:*:* | ||
<= 0.16.9CPE matchmatch criteria | cpe:2.3:a:sheetjs:sheetjs_pro:*:*:*:*:*:node.js:*:* | ||
< 21.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.