MEDIUM5.3
GHSA-r8f7-9pfq-mjmv
Improper Certificate Validation in node-sass
Quick fix
GHSA-r8f7-9pfq-mjmv — node-sass: upgrade to the fixed version with the command below.
npm install node-sass@7.0.0Details
Certificate validation in node-sass 2.0.0 to 6.0.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-24025[ADVISORY]
- https://github.com/sass/node-sass/issues/3067[WEB]
- https://github.com/sass/node-sass/pull/3149[WEB]
- https://github.com/sass/node-sass/pull/567#issuecomment-656609236[WEB]
- https://github.com/sass/node-sass/commit/0a21792803639851b480fbd8cbcb5540ef974387[WEB]
- https://github.com/sass/node-sass[PACKAGE]
- https://github.com/sass/node-sass/releases/tag/v7.0.0[WEB]