CVE-2018-11693 (High) detected in node-sass-3.13.1.tgz, node-sass15fe42ed92dea8e086e7837e53ecd8190c0179b9 #33
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2018-11693 - High Severity Vulnerability
Vulnerable Libraries - node-sass-3.13.1.tgz, node-sass15fe42ed92dea8e086e7837e53ecd8190c0179b9
node-sass-3.13.1.tgz
Wrapper around libsass
Library home page: https://registry.npmjs.org/node-sass/-/node-sass-3.13.1.tgz
Path to dependency file: /html_site_template_customer/fashi/Source/jquery-nice-select-1.1.0/jquery-nice-select-1.1.0/jquery-nice-select-1.1.0/package.json
Path to vulnerable library: /html_site_template_customer/fashi/Source/SlickNav-master/SlickNav-master/node_modules/node-sass/package.json,/html_site_template_customer/fashi/Source/SlickNav-master/SlickNav-master/node_modules/node-sass/package.json,/html_site_template_customer/fashi/Source/SlickNav-master/SlickNav-master/node_modules/node-sass/package.json,/html_site_template_customer/fashi/Source/SlickNav-master/SlickNav-master/node_modules/node-sass/package.json,/html_site_template_customer/fashi/Source/SlickNav-master/SlickNav-master/node_modules/node-sass/package.json
Dependency Hierarchy:
Found in HEAD commit: 08ba0922f3668b139df2a365e01b4d3e57faef86
Found in base branch: master
Vulnerability Details
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Publish Date: 2018-06-04
URL: CVE-2018-11693
CVSS 3 Score Details (8.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2018-06-04
Fix Resolution (node-sass): 4.11.0
Direct dependency fix Resolution (grunt-sass): 2.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: