CVE-2018-20822: Medium severity libsass vulnerability
Published Apr 23, 2019
·Updated
LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::ComplexSelector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp).
Affected Software
1 affected component
Sass-lang Libsass=3.5.4
Event History
Apr 23, 2019
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-20822.
2
What is the severity of CVE-2018-20822?
The severity of CVE-2018-20822 is medium with a CVSS severity score of 6.5.
3
How does CVE-2018-20822 allow attackers to cause a denial-of-service?
CVE-2018-20822 allows attackers to cause a denial-of-service through uncontrolled recursion in Sass::Complex_Selector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp.
4
Which version of LibSass is affected by CVE-2018-20822?
Version 3.5.4 of LibSass is affected by CVE-2018-20822.
5
Is there a fix available for CVE-2018-20822?
Yes, there is a fix available for CVE-2018-20822. It is recommended to update to a version of LibSass that is not affected by this vulnerability.