Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2021-32809 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2018-11799 Vulnerability in maven package org.apache.oozie:oozie-core
CVE-2018-8026 Vulnerability in maven package org.apache.solr:solr-core
CVE-2016-4432 Vulnerability in maven package org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol
CVE-2018-15494 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox