OSV 1.4.0 · github-reviewed · 修改于 2021-09-29 00:08
发布时间
2020-09-12 05:12
GitHub 审查时间
2020-09-01 02:42
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-9v62-24cr-58cx/GHSA-9v62-24cr-58cx.json
Affected versions of node-sass are vulnerable to Denial of Service (DoS). Crafted objects passed to the renderSync function may trigger C++ assertions in CustomImporterBridge::get_importer_entry and CustomImporterBridge::post_process_return_value that crash the Node process. This may allow attackers to crash the system's running Node process and lead to Denial of Service.
Upgrade to version 4.13.1 or later