Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2019-5427 Vulnerability in maven package c3p0:c3p0
CVE-2023-42795 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2016-1000342 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2019-10282 Vulnerability in maven package hudson.plugins.klaros:klaros-testmanagement