Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2021-29300 Vulnerability in npm package opened
CVE-2016-6809 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2018-3818 Vulnerability in npm package kibana
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-pmml-examples
CVE-2022-47105 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system