This repository has been archived by the owner on Oct 23, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
CVE-2018-19827 (High) detected in node-sass-4.14.1.tgz, node-sassv4.13.1 #46
Labels
security vulnerability
Security vulnerability detected by WhiteSource
Comments
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
CVE-2018-19827 - High Severity Vulnerability
node-sass-4.14.1.tgz
Wrapper around libsass
Library home page: https://registry.npmjs.org/node-sass/-/node-sass-4.14.1.tgz
Path to dependency file: resume/package.json
Path to vulnerable library: resume/node_modules/node-sass/package.json
Dependency Hierarchy:
Found in HEAD commit: 5f3662aa801596074e7b1252738e340f55c2c760
In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact.
Publish Date: 2018-12-03
URL: CVE-2018-19827
Base Score Metrics:
Type: Upgrade version
Origin: sass/libsass#2784
Release Date: 2019-08-29
Fix Resolution: LibSass - 3.6.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: