Description
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Remediation
References
https://github.com/sass/node-sass/pull/567#issuecomment-656609236
Related Vulnerabilities
CVE-2017-12159 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-17519 Vulnerability in maven package org.apache.flink:flink-runtime_2.11
CVE-2017-16028 Vulnerability in npm package react-native-meteor-oauth
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-38179 Vulnerability in maven package io.ktor:ktor-utils