CVE-2020-24025 PUBLISHED

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

EPSS 0.49% · 65.4th percentile

Risk Scores

EPSS Score
0.49%
65.4th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10node-node-sass9.0.0+git20240131.6081731+dfsg-3, 0
Ubuntu:20.04:LTSnode-node-sass4.13.1-1, 4.13.1-3, 0
Ubuntu:22.04:LTSnode-node-sass*, 7.0.1+git20211229.3bb51da+dfsg-1, 0
Ubuntu:24.04:LTSnode-node-sass*, 0, *

Timeline

References

Open in Interactive Console →