Description
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Remediation
References
https://github.com/sass/libsass/issues/2664
https://github.com/sass/libsass/pull/2631
https://github.com/sass/libsass/releases
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package org.wildfly.swarm:bootstrap
CVE-2022-1243 Vulnerability in maven package org.webjars.npm:urijs
CVE-2022-4640 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-hikari-dbcp-service
CVE-2023-40315 Vulnerability in maven package org.opennms:opennms-webapp-rest