Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24025

Опубликовано: 11 янв. 2021
Источник: redhat
CVSS3: 5.3

Описание

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

A flaw was found in nodejs-node-sass. Certificate validation is disabled when requesting binaries even if the user is not specifying an alternative download path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1kialiNot affected
OpenShift Service Mesh 1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.0servicemesh-grafanaNot affected
Red Hat Advanced Cluster Management for Kubernetes 2console-headerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2grc-uiNot affected
Red Hat Advanced Cluster Management for Kubernetes 2mcm-topologyNot affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1921882nodejs-node-sass: Certificate validation is disabled when requesting binaries

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

CVSS3: 5.3
nvd
около 5 лет назад

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

CVSS3: 5.3
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 5 лет назад

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when r ...

CVSS3: 5.3
github
почти 4 года назад

Improper Certificate Validation in node-sass

5.3 Medium

CVSS3