CVE-2024-22363: SheetJS Regular Expression Denial of Service (ReDoS)
(updated )
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package xlsx
are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-22363 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →