CVE-2018-11698 (High) detected in node-sass-8.0.0.tgz #1068
Labels
cve
Security vulnerabilities detected by Dependabot or Mend
high severity
High severity CVE
Mend: dependency security vulnerability
Security vulnerability detected by Mend
v2.0.0
CVE-2018-11698 - High Severity Vulnerability
Wrapper around libsass
Library home page: https://registry.npmjs.org/node-sass/-/node-sass-8.0.0.tgz
Dependency Hierarchy:
Found in HEAD commit: 4fd064970b66ce555f48c22dfab6ed965d0e260a
Found in base branch: main
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Publish Date: 2018-06-04
URL: CVE-2018-11698
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-r5m8-frrg-389w
Release Date: 2018-06-04
Fix Resolution: node-sass - 4.14.0
The text was updated successfully, but these errors were encountered: