Improper Certificate Validation
Affecting node-sass package, versions >=2.0.0
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
node-sass is a Node.js bindings package for libsass.
Affected versions of this package are vulnerable to Improper Certificate Validation. Certificate validation is disabled by default when requesting binaries, even if the user is not specifying an alternative download path.
Remediation
There is no fixed version for node-sass
.
References
CVSS Score
5.3
medium severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- Credit
- Lorenzo Stella
- CVE
- CVE-2020-24025
- CWE
- CWE-295
- Snyk ID
- SNYK-JS-NODESASS-1059081
- Disclosed
- 12 Jan, 2021
- Published
- 12 Jan, 2021