SB2020011417 - Denial of Service in node-sass NPM package



SB2020011417 - Denial of Service in node-sass NPM package

Published: January 14, 2020

Security Bulletin ID SB2020011417
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: N/A)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

Crafted objects passed to the renderSync function may trigger C++ assertions in CustomImporterBridge::get_importer_entry and CustomImporterBridge::post_process_return_value that crash the Node process. This may allow attackers to crash the system's running Node process and lead to Denial of Service.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.