Description
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Remediation
References
https://github.com/sass/libsass/issues/2664
https://github.com/sass/libsass/pull/2631
https://github.com/sass/libsass/releases
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror
CVE-2022-24858 Vulnerability in npm package next-auth
CVE-2019-16869 Vulnerability in maven package io.netty:netty-all
CVE-2021-23416 Vulnerability in npm package curly-bracket-parser
CVE-2013-2251 Vulnerability in maven package org.apache.struts:struts2-core