PT-2021-10998 · Npm+3 · Node-Sass+3

Liujinghao

+1

·

Published

2021-01-11

·

Updated

2022-04-01

·

CVE-2020-24025

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: node-sass versions 2.0.0 through 6.0.1
Description: The issue is related to disabled certificate validation in node-sass when requesting binaries, even if the user does not specify an alternative download path. This affects certain versions of eZ Platform, ezsystems/ezplatform, and ezsystems/ezplatform-page-builder. The maintainers resolved the issue by replacing node-sass with sass.
Recommendations: For node-sass versions 2.0.0 through 6.0.1, consider replacing node-sass with sass 1.32.13 or a later version to resolve the issue. For eZ Platform v2.5, update to a version that uses sass instead of node-sass. At the moment, there is no information about other specific fixes for this issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-27653
CVE-2020-24025
GHSA-6V6P-G8CG-2HGG
GHSA-R8F7-9PFQ-MJMV

Affected Products

Debian
Ez Platform
Node-Sass
Sass