Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2015-0254 Vulnerability in maven package javax.servlet:jstl
CVE-2023-26136 Vulnerability in maven package org.webjars.bowergithub.salesforce:tough-cookie
CVE-2018-6591 Vulnerability in npm package converse.js
CVE-2023-32007 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2019-10336 Vulnerability in maven package org.jenkins-ci.plugins:electricflow