PT-2021-10998 · Npm+3 · Node-Sass+3
Liujinghao
+1
·
Published
2021-01-11
·
Updated
2022-04-01
·
CVE-2020-24025
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
node-sass versions 2.0.0 through 6.0.1
Description:
The issue is related to disabled certificate validation in node-sass when requesting binaries, even if the user does not specify an alternative download path. This affects certain versions of eZ Platform, ezsystems/ezplatform, and ezsystems/ezplatform-page-builder. The maintainers resolved the issue by replacing node-sass with sass.
Recommendations:
For node-sass versions 2.0.0 through 6.0.1, consider replacing node-sass with sass 1.32.13 or a later version to resolve the issue.
For eZ Platform v2.5, update to a version that uses sass instead of node-sass.
At the moment, there is no information about other specific fixes for this issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Ez Platform
Node-Sass
Sass