PT-2020-21211 · Node · Node-Sass

Published

2020-09-11

·

Updated

2020-09-11

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions node-sass versions prior to 4.13.1
Description The issue allows attackers to crash the system's running Node process, leading to Denial of Service. This can be achieved by passing crafted objects to the renderSync function, which may trigger C++ assertions in CustomImporterBridge::get importer entry and CustomImporterBridge::post process return value that crash the Node process.
Recommendations Upgrade to version 4.13.1 or later.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-9V62-24CR-58CX

Affected Products

Node-Sass