Description
There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, leading to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1482331
Related Vulnerabilities
CVE-2022-29253 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-1003077 Vulnerability in maven package org.jenkins-ci.plugins:audit2db
CVE-2022-23596 Vulnerability in maven package com.github.junrar:junrar
CVE-2019-1010266 Vulnerability in maven package org.webjars:lodash
CVE-2023-50709 Vulnerability in npm package @cubejs-backend/api-gateway