-
-
Notifications
You must be signed in to change notification settings - Fork 8k
Open
Description
[Security] Prototype Pollution in sheetJS
Affected version: 0.19.3
Description
All versions of SheetJS CE through 0.19.2 are vulnerable to "Prototype Pollution" when reading specially crafted files. Workflows that do not read arbitrary files (for example, exporting data to spreadsheet files) are unaffected.
References
https://nvd.nist.gov/vuln/detail/CVE-2023-30533
https://cdn.sheetjs.com/advisories/CVE-2023-30533
https://git.sheetjs.com/sheetjs/sheetjs/src/branch/master/CHANGELOG.md
rahulkj, rios-cris, Giggs3244, UNIDY2002, DecisionFocus and 58 more
Metadata
Metadata
Assignees
Labels
No labels