Junglewise Threat Intelligence

CVE-2024-22363: SheetJS Regular Expression Denial of Service

CVE-2024-22363 · Severity: low · CVSS 3.1 · Published 2024-04-05

Technologies: xlsx (npm). Vendors: npm.

Executive brief

SheetJS is a popular JavaScript library used for reading, writing, and manipulating spreadsheet files in web applications. Versions before 0.20.2 contain a flaw in how they process certain text patterns using regular expressions. An attacker can send specially crafted input that causes the library to consume excessive CPU resources, making the application slow or completely unresponsive and disrupting service for legitimate users. No authentication is required to exploit this vulnerability.

Technical details

This vulnerability is a Regular Expression Denial of Service (ReDoS) attack targeting an inefficient regular expression pattern with nested quantifiers (CWE-1333). The vulnerable regex pattern uses backtracking that can exhibit exponential time complexity when processing certain input strings that fail to match the pattern. Attack vector is network-based with no authentication or user interaction required (CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). An attacker can cause the application to hang or become unresponsive by providing a crafted input string to any function that uses this vulnerable regex. The fix is available in version 0.20.2 and later, which can be obtained from the SheetJS CDN at https://cdn.sheetjs.com/. The npm package xlsx is no longer maintained, but the updated version can be downloaded directly from the CDN.

Affected products

  • SheetJS SheetJS Community Edition < 0.20.2
  • SheetJS xlsx (npm package) < 0.20.2

Timeline

  • 2024-04-05: disclosed
  • 2024-04-08: advisory: GitHub security advisory reviewed
  • 2024-04-04: patched: Version 0.20.2 released with fix

References

Related threats