-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Package issue exists @ Npm-node-sass-4.13.0 in branch master
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Namespace: Abdul1110
Repository: TEST_ORION
Repository Url: https://github.com/Abdul1110/TEST_ORION
CxAST-Project: Abdul1110/TEST_ORION
CxAST platform scan: 19490220-b272-4b92-94fa-50af22248f60
Branch: master
Application: TEST_ORION
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-125
Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 5.0.0
References
Advisory
Issue
Release Note
Pull request
Commit