This repository has been archived by the owner on Oct 23, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0 #50
Labels
security vulnerability
Security vulnerability detected by WhiteSource
Comments
mend-bolt-for-github
bot
added
the
security vulnerability
Security vulnerability detected by WhiteSource
label
Nov 2, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 3, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 4, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 6, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 8, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 9, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Nov 10, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Dec 1, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
Dec 1, 2020
mend-bolt-for-github
bot
changed the title
CVE-2018-11697 (High) detected in opennmsopennms-source-25.1.0-1, CSS::Sassv3.4.11
CVE-2018-11697 (High) detected in node-sassv4.13.1, CSS::Sassv3.6.0
Dec 3, 2020
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
CVE-2018-11697 - High Severity Vulnerability
Vulnerable Libraries - node-sassv4.13.1, CSS::Sassv3.6.0
Vulnerability Details
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Publish Date: 2018-06-04
URL: CVE-2018-11697
CVSS 3 Score Details (8.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11697
Release Date: 2019-09-01
Fix Resolution: LibSass - 3.6.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: