Описание
Improper Certificate Validation in node-sass
Certificate validation in node-sass 2.0.0 to 6.0.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-24025
- https://github.com/sass/node-sass/issues/3067
- https://github.com/sass/node-sass/pull/3149
- https://github.com/sass/node-sass/pull/567#issuecomment-656609236
- https://github.com/sass/node-sass/commit/0a21792803639851b480fbd8cbcb5540ef974387
- https://github.com/sass/node-sass/releases/tag/v7.0.0
Пакеты
node-sass
>= 2.0.0, < 7.0.0
7.0.0
Связанные уязвимости
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when r ...