You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Dec 9, 2023. It is now read-only.
Path to vulnerable library: Website/node_modules/node-sass/package.json
Dependency Hierarchy:
gulp-sass-4.0.1.tgz (Root Library)
❌ node-sass-4.8.3.tgz (Vulnerable Library)
Vulnerability Details
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
CVE-2020-24025 - Medium Severity Vulnerability
Wrapper around libsass
Library home page: https://registry.npmjs.org/node-sass/-/node-sass-4.8.3.tgz
Path to dependency file: /Website/package.json
Path to vulnerable library: Website/node_modules/node-sass/package.json
Dependency Hierarchy:
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Publish Date: 2021-01-11
URL: CVE-2020-24025
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with WhiteSource here