This repository has been archived by the owner on Oct 23, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1 #47
Labels
security vulnerability
Security vulnerability detected by WhiteSource
Comments
mend-bolt-for-github
bot
added
the
security vulnerability
Security vulnerability detected by WhiteSource
label
Nov 2, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 3, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 4, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Dec 1, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
Dec 1, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-19838 (Medium) detected in opennmsopennms-source-25.1.0-1, node-sass-4.14.1.tgz
CVE-2018-19838 (Medium) detected in node-sass-4.14.1.tgz, node-sassv4.13.1
Dec 3, 2020
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
CVE-2018-19838 - Medium Severity Vulnerability
Vulnerable Libraries - node-sass-4.14.1.tgz, node-sassv4.13.1
node-sass-4.14.1.tgz
Wrapper around libsass
Library home page: https://registry.npmjs.org/node-sass/-/node-sass-4.14.1.tgz
Path to dependency file: resume/package.json
Path to vulnerable library: resume/node_modules/node-sass/package.json
Dependency Hierarchy:
Found in HEAD commit: 5f3662aa801596074e7b1252738e340f55c2c760
Vulnerability Details
In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, as demonstrated by recursive calls involving clone(), cloneChildren(), and copy().
Publish Date: 2018-12-04
URL: CVE-2018-19838
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://github.com/sass/libsass/blob/3.6.0/src/ast.cpp
Release Date: 2019-07-01
Fix Resolution: LibSass - 3.6.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: