CVE-2023-7101
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,8331
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
94
Improper Control of Generation of Code ('Code Injection')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Non-Repudiation
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Hide Activities
Applicable Platforms
Languages:
Interpreted
Technologies:
AI/ML
95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Access Control
Integrity
Availability
Other
Non-Repudiation
Potential Impacts:
Read Files Or Directories
Read Application Data
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Hide Activities
Applicable Platforms
Languages:
Interpreted, Java, JavaScript, Perl, PHP, Python, Ruby
Technologies:
AI/ML
Operating System
Debian Linux by Debian
CPE Identifier
View Detailed Analysis
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Spreadsheet\ by Jmcnamara
Version Range Affected
To
0.65
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:jmcnamara:spreadsheet\:\:parseexcel:*:*:*:*:*:perl:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Fedora by Fedoraproject
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Fedora by Fedoraproject
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023…
https://github.com/haile01/perl_spreadsheet_excel_rce_poc
https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150…
https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c5…
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-202…
https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html
https://lists.fedoraproject.org/archives/list/[email protected]…
https://lists.fedoraproject.org/archives/list/[email protected]…
https://metacpan.org/dist/Spreadsheet-ParseExcel
https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules…
https://www.cve.org/CVERecord?id=CVE-2023-7101
http://www.openwall.com/lists/oss-security/2023/12/29/4
https://github.com/haile01/perl_spreadsheet_excel_rce_poc
https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150…
https://github.com/jmcnamara/spreadsheet-parseexcel/commit/bd3159277e745468e2c5…
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-202…
https://lists.debian.org/debian-lts-announce/2023/12/msg00025.html
https://lists.fedoraproject.org/archives/list/[email protected]…
https://lists.fedoraproject.org/archives/list/[email protected]…
https://metacpan.org/dist/Spreadsheet-ParseExcel
https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules…
https://www.cve.org/CVERecord?id=CVE-2023-7101
http://www.openwall.com/lists/oss-security/2023/12/29/4