Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2020-7676 Vulnerability in maven package org.webjars.bowergithub.angular:angular
CVE-2023-40339 Vulnerability in maven package org.jenkins-ci.plugins:config-file-provider
CVE-2020-7642 Vulnerability in npm package lazysizes
CVE-2021-35513 Vulnerability in maven package org.webjars.npm:mermaid
CVE-2021-46089 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core