cve-2023-7101
HIGH cisa_known_exploited
Description
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.
Timeline
- Published
- 2024-01-02
- Last Modified
- 2024-01-02
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
{
"cvss": 0.0,
"datePublished": "2024-01-02",
"dateUpdated": "2024-01-02",
"description": "Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.",
"dueDate": "2024-01-23",
"id": "CVE-2023-7101",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://metacpan.org/dist/Spreadsheet-ParseExcel and Barracuda's specific implementation and fix for their downstream issue CVE-2023-7102 at https://www.barracuda.com/company/legal/esg-vulnerability; https://nvd.nist.gov/vuln/detail/CVE-2023-7101",
"product": "Spreadsheet::ParseExcel",
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
"severity": "HIGH",
"source": "cisa_known_exploited",
"title": "Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
"vendor": "Spreadsheet::ParseExcel"
}
Enrichment data
Aggregated bundle (all enrichments)