Skip to content
This repository has been archived by the owner on May 22, 2024. It is now read-only.

[Snyk: High] Uncontrolled Recursion node-sass (Due 3/28/2022) #660

Closed
Tracked by #137
patphongs opened this issue Jan 27, 2022 · 1 comment
Closed
Tracked by #137

[Snyk: High] Uncontrolled Recursion node-sass (Due 3/28/2022) #660

patphongs opened this issue Jan 27, 2022 · 1 comment
Assignees
Labels
Security: moderate Remediate within 60 days
Milestone

Comments

@patphongs
Copy link
Member

Vulnerable module: node-sass
Introduced through: node-sass@7.0.1

Detailed paths
Introduced through: node-sass@7.0.1

Overview
node-sass is a Node.js bindings package for libsass.

Affected versions of this package are vulnerable to Uncontrolled Recursion via Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp. Note: node-sass is affected by this vulnerability due to its bundled usage of the libsass package.

@pkfec
Copy link
Contributor

pkfec commented Feb 24, 2022

node-sass is not vulnerable package anymore here:https://app.snyk.io/org/fecgov/project/5e01de94-91bc-43d8-90b1-8843384b4b26

node-sass package is moved to dev dependencies list in a recent pr# #663.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Security: moderate Remediate within 60 days
Projects
None yet
Development

No branches or pull requests

3 participants