Improper Certificate Validation in node-sass affects eZ Platform
Moderate severity
GitHub Reviewed
Published
Mar 21, 2022
in
ezsystems/ezplatform-admin-ui
•
Updated Jan 11, 2023
Package
Affected versions
>= 1.5.0, < 1.5.27
Patched versions
1.5.27
Description
Published to the GitHub Advisory Database
Apr 1, 2022
Reviewed
Apr 1, 2022
Last updated
Jan 11, 2023
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path. This affects eZ Platform v2.5 only. The maintainers resolved it by replacing node-sass 4.11 with sass 1.32.13. This issue also affects ezsystems/ezplatform and ezsystems/ezplatform-page-builder.
References