Sheetjs latest version (0.18.5) is reporting vulnerability #3012

Closed
opened 2023-10-16 05:17:15 +00:00 by Swetha · 1 comment

Hi,

We are using the latest sheetjs version 0.18.5(https://www.npmjs.com/package/xlsx) and our black duck hub tool is reporting the below vulnerability due to which we have to find alternate package.

This is the vulnerability reported which has a score of 7.8

CVE-2023-30533
(BDSA-2023-0967)
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

Any help in this? Any plans to remdiate this from your side? We have been using this package for the last two years, we do not want to remove its usage due to this vulnerability.

Hi, We are using the latest sheetjs version 0.18.5(https://www.npmjs.com/package/xlsx) and our black duck hub tool is reporting the below vulnerability due to which we have to find alternate package. This is the vulnerability reported which has a score of 7.8 CVE-2023-30533 (BDSA-2023-0967) SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected. Any help in this? Any plans to remdiate this from your side? We have been using this package for the last two years, we do not want to remove its usage due to this vulnerability.
Owner
https://docs.sheetjs.com/docs/getting-started/installation/nodejs
Sign in to join this conversation.
No Milestone
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: sheetjs/sheetjs#3012
No description provided.