Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2015-8859 Vulnerability in npm package send
CVE-2016-10620 Vulnerability in npm package atom-node-module-installer
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash
CVE-2023-34468 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-common