Junglewise Threat Intelligence

node-sass denial of service in renderSync

Severity: low · CVSS 3.1 · Published 2020-09-11

Vendors: npm.

Executive brief

node-sass is a Node.js library that compiles Sass stylesheets to CSS. A vulnerability in the renderSync function allows attackers to crash the Node process by passing specially crafted objects, resulting in service unavailability for applications using the library.

Technical details

node-sass versions 3.3.0 through 4.13.0 contain a denial of service vulnerability in the C++ CustomImporterBridge component. The vulnerability is triggered when crafted objects are passed to the renderSync function, causing unhandled C++ assertions in CustomImporterBridge::get_importer_entry and CustomImporterBridge::post_process_return_value that crash the Node process. The attack requires no authentication and is network-reachable if the application exposes the renderSync function via a web service. The fix was applied in version 4.13.1.

Affected products

  • Sass node-sass 3.3.0 to 4.13.0

Timeline

  • 2020-09-11: disclosed

References

Related threats