MEDIUM5.3
GHSA-6v6p-g8cg-2hgg
Improper Certificate Validation in node-sass affects eZ Platform
Quick fix
GHSA-6v6p-g8cg-2hgg — ezsystems/ezplatform-admin-ui: upgrade to the fixed version with the command below.
composer require ezsystems/ezplatform-admin-ui:^1.5.27Details
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path. This affects eZ Platform v2.5 only. The maintainers resolved it by replacing node-sass 4.11 with sass 1.32.13. This issue also affects ezsystems/ezplatform and ezsystems/ezplatform-page-builder.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezsystems/ezplatform-admin-ui
Introduced in:
1.5.0Fixed in: 1.5.27Fix
composer require ezsystems/ezplatform-admin-ui:^1.5.27References
- https://github.com/ezsystems/ezplatform-admin-ui/security/advisories/GHSA-6v6p-g8cg-2hgg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-24025[ADVISORY]
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-002-vulnerability-in-node-sass[WEB]
- https://github.com/advisories/GHSA-r8f7-9pfq-mjmv[ADVISORY]
- https://github.com/ezsystems/ezplatform-admin-ui[PACKAGE]
- https://github.com/ezsystems/ezplatform-admin-ui/releases/tag/v1.5.27[WEB]