
Cloud Vulnerability DB
A community-led vulnerabilities database
Certificate validation in node-sass versions 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path. The vulnerability was discovered in 2020 and assigned CVE-2020-24025 (NVD).
The vulnerability exists in the getBinaryUrl function where certificate validation is disabled by default when requesting binaries from github.com, even when users are not specifying an alternative download path. This occurs due to the rejectUnauthorized flag being set to false in the installation script. The vulnerability has a CVSS v3.1 Base Score of 5.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N (NVD).
The vulnerability allows attackers to perform man-in-the-middle attacks during the binary download process, as the certificate validation is disabled by default. This could potentially lead to the download of malicious binaries instead of the legitimate node-sass binaries (GitHub Discussion).
Users should upgrade to versions after 4.14.1 where the certificate validation has been properly implemented. For users who need to work with self-signed certificates, it is recommended to properly import the certificates rather than disabling certificate validation entirely (GitHub Discussion).
The security community has expressed concerns about the implementation, with several developers on GitHub suggesting that disabling certificate validation should not be the default behavior and should instead be made optional through environment variables (GitHub Discussion).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."