GithubHelp home page GithubHelp logo

pritam-patil / react-starter-kit Goto Github PK

View Code? Open in Web Editor NEW
1.0 1.0 0.0 2.22 MB

Rapid prototyping starter kit for ReactJS with Material-UI as UI library and webpack as bundler

License: Other

JavaScript 85.69% HTML 13.38% CSS 0.93%

react-starter-kit's Issues

WS-2019-0032 Medium Severity Vulnerability detected by WhiteSource

WS-2019-0032 - Medium Severity Vulnerability

Vulnerable Library - js-yaml-3.7.0.tgz

YAML 1.2 parser and serializer

path: /tmp/git/react-material-webpack-boiler/node_modules/postcss-svgo/node_modules/js-yaml/package.json

Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-3.7.0.tgz

Dependency Hierarchy:

  • css-loader-0.28.11.tgz (Root Library)
    • cssnano-3.10.0.tgz
      • postcss-svgo-2.1.6.tgz
        • svgo-0.7.2.tgz
          • โŒ js-yaml-3.7.0.tgz (Vulnerable Library)

Found in HEAD commit: 33b3f5702d5db3b85059ac03c0021f5c6bb8c81d

Vulnerability Details

Versions js-yaml prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service.

Publish Date: 2019-03-26

URL: WS-2019-0032

CVSS 2 Score Details (5.0)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/788/versions

Release Date: 2019-03-26

Fix Resolution: 3.13.0


Step up your Open Source Security Game with WhiteSource here

CVE-2019-6286 Medium Severity Vulnerability detected by WhiteSource

CVE-2019-6286 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.

Publish Date: 2019-01-14

URL: CVE-2019-6286

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11695 High Severity Vulnerability detected by WhiteSource

CVE-2018-11695 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.2. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

Publish Date: 2018-06-04

URL: CVE-2018-11695

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-19838 Medium Severity Vulnerability detected by WhiteSource

CVE-2018-19838 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, as demonstrated by recursive calls involving clone(), cloneChildren(), and copy().

Publish Date: 2018-12-04

URL: CVE-2018-19838

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19838

Fix Resolution: 3.5.5


Step up your Open Source Security Game with WhiteSource here

CVE-2019-6283 Medium Severity Vulnerability detected by WhiteSource

CVE-2019-6283 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.

Publish Date: 2019-01-14

URL: CVE-2019-6283

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

WS-2019-0019 Medium Severity Vulnerability detected by WhiteSource

WS-2019-0019 - Medium Severity Vulnerability

Vulnerable Library - braces-1.8.5.tgz

Fastest brace expansion for node.js, with the most complete support for the Bash 4.3 braces specification.

path: /tmp/git/react-material-webpack-boiler/node_modules/jest-haste-map/node_modules/braces/package.json

Library home page: https://registry.npmjs.org/braces/-/braces-1.8.5.tgz

Dependency Hierarchy:

  • babel-jest-23.6.0.tgz (Root Library)
    • babel-plugin-istanbul-4.1.6.tgz
      • test-exclude-4.2.3.tgz
        • micromatch-2.3.11.tgz
          • โŒ braces-1.8.5.tgz (Vulnerable Library)

Vulnerability Details

Version of braces prior to 2.3.1 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.

Publish Date: 2019-03-25

URL: WS-2019-0019

CVSS 2 Score Details (5.0)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/786

Release Date: 2019-02-21

Fix Resolution: 2.3.1


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11499 High Severity Vulnerability detected by WhiteSource

CVE-2018-11499 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.

Publish Date: 2018-05-26

URL: CVE-2018-11499

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-19826 Medium Severity Vulnerability detected by WhiteSource

CVE-2018-19826 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::String_Quoted*) stack frame) may cause a Denial of Service via crafted sass input files with stray '&' or '/' characters.

Publish Date: 2018-12-03

URL: CVE-2018-19826

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11693 High Severity Vulnerability detected by WhiteSource

CVE-2018-11693 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

Publish Date: 2018-06-04

URL: CVE-2018-11693

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-19839 Medium Severity Vulnerability detected by WhiteSource

CVE-2018-19839 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

Publish Date: 2018-12-04

URL: CVE-2018-19839

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19839

Fix Resolution: 3.5.5


Step up your Open Source Security Game with WhiteSource here

CVE-2018-19797 Medium Severity Vulnerability detected by WhiteSource

CVE-2018-19797 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

Publish Date: 2018-12-03

URL: CVE-2018-19797

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11697 High Severity Vulnerability detected by WhiteSource

CVE-2018-11697 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

Publish Date: 2018-06-04

URL: CVE-2018-11697

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11694 High Severity Vulnerability detected by WhiteSource

CVE-2018-11694 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

Publish Date: 2018-06-04

URL: CVE-2018-11694

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-20190 Medium Severity Vulnerability detected by WhiteSource

CVE-2018-20190 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cpp may cause a Denial of Service (application crash) via a crafted sass input file.

Publish Date: 2018-12-17

URL: CVE-2018-20190

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-19827 High Severity Vulnerability detected by WhiteSource

CVE-2018-19827 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact.

Publish Date: 2018-12-03

URL: CVE-2018-19827

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2019-6284 Medium Severity Vulnerability detected by WhiteSource

CVE-2019-6284 - Medium Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.

Publish Date: 2019-01-14

URL: CVE-2019-6284

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

CVE-2018-11698 High Severity Vulnerability detected by WhiteSource

CVE-2018-11698 - High Severity Vulnerability

Vulnerable Library - node-sassv4.11.0

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (125)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/unchecked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/base.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operation.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/error_handling.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/emitter.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/output.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_def_macros.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/paths.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/check_nesting.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/json.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/units.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8/checked.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/listize.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass2scss.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/eval.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/expand.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/factory.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/boolean.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/source_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/value.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/callback_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/node.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/operators.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast_fwd_decl.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/parser.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/constants.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/list.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cssize.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/util.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_function_bridge.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/custom_importer_bridge.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/bind.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/inspect.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/backtrace.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/extend.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debugger.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/cencode.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/number.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/color.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/c99func.c
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/position.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/remove_placeholders.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_values.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/values.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass2scss.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/null.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/ast.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/include/sass/context.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/color_maps.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/script/test-leaks.pl
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/memory/SharedPtr.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_c.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/sass_types/map.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/to_value.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/file.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/environment.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/binding.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/sass_context.cpp
  • /react-material-webpack-boiler/node_modules/node-sass/src/libsass/src/debug.hpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

Publish Date: 2018-06-04

URL: CVE-2018-11698

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.