Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2017-5662 Vulnerability in maven package batik:batik-dom
CVE-2019-10345 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2022-43441 Vulnerability in npm package sqlite3
CVE-2019-10769 Vulnerability in npm package safer-eval
CVE-2016-3092 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core