CVE-2020-24025: Medium severity sass vulnerability
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Other sources
node-sass could allow a remote attacker to bypass security restrictions, caused by the disablement of certificate validation when requesting binaries even if the user is not specifying an alternative download path. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass access restrictions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24025?
CVE-2020-24025 is classified as a medium-severity vulnerability due to the potential for remote attackers to bypass security restrictions.
How do I fix CVE-2020-24025?
To fix CVE-2020-24025, you should upgrade node-sass to a version higher than 4.14.1 where certificate validation is enabled.
Which versions of node-sass are affected by CVE-2020-24025?
CVE-2020-24025 affects node-sass versions from 2.0.0 to 4.14.1.
What products are affected by CVE-2020-24025?
CVE-2020-24025 impacts node-sass as well as IBM products such as Data Virtualization and Watson Query on Cloud Pak for Data up to specific versions.
Can CVE-2020-24025 be exploited remotely?
Yes, CVE-2020-24025 can be exploited by remote attackers who can take advantage of the disabled certificate validation.