Description
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471786
Related Vulnerabilities
CVE-2022-2064 Vulnerability in npm package nocodb
CVE-2023-38704 Vulnerability in npm package import-in-the-middle
CVE-2014-0050 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone
CVE-2021-21165 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-40810 Vulnerability in maven package org.opencrx:opencrx-core-models