Description
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471786
Related Vulnerabilities
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-8298 Vulnerability in npm package fs-path
CVE-2022-24891 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2021-31407 Vulnerability in maven package com.vaadin:flow-server
CVE-2023-25764 Vulnerability in maven package org.jenkins-ci.plugins:email-ext