Kreshnik/ninjecture

CVE-2018-11697 High Severity Vulnerability detected by WhiteSource

Opened this issue ยท 0 comments

CVE-2018-11697 - High Severity Vulnerability

Vulnerable Library - node-sassv4.9.4

๐ŸŒˆ Node.js bindings to libsass

Library home page: https://github.com/sass/node-sass.git

Library Source Files (43)

* The source files were matched to this source library based on a best effort match. Source libraries are selected from a list of probable public libraries.

  • /ninjecture/node_modules/node-sass/src/sass_context_wrapper.h
  • /ninjecture/node_modules/node-sass/src/sass_types/map.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/b64/encode.h
  • /ninjecture/node_modules/node-sass/src/libsass/src/base64vlq.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/c99func.c
  • /ninjecture/node_modules/node-sass/src/libsass/test/test_subset_map.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/color.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/backtrace.hpp
  • /ninjecture/node_modules/node-sass/src/custom_function_bridge.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/test/test_node.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/paths.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/sass_values.hpp
  • /ninjecture/node_modules/node-sass/src/sass_types/number.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/boolean.h
  • /ninjecture/node_modules/node-sass/src/sass_context_wrapper.cpp
  • /ninjecture/node_modules/node-sass/src/custom_importer_bridge.cpp
  • /ninjecture/node_modules/node-sass/src/binding.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/test/test_unification.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/position.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/plugins.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/sass_value_wrapper.h
  • /ninjecture/node_modules/node-sass/src/sass_types/list.h
  • /ninjecture/node_modules/node-sass/src/libsass/src/prelexer.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/position.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/null.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/string.cpp
  • /ninjecture/node_modules/node-sass/src/sass_types/boolean.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/contrib/plugin.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/plugins.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/lexer.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/sass_util.cpp
  • /ninjecture/node_modules/node-sass/src/custom_importer_bridge.h
  • /ninjecture/node_modules/node-sass/src/sass_types/color.h
  • /ninjecture/node_modules/node-sass/src/libsass/test/test_superselector.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/utf8_string.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/cencode.c
  • /ninjecture/node_modules/node-sass/src/libsass/src/sass_functions.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/debug.hpp
  • /ninjecture/node_modules/node-sass/src/libsass/src/utf8_string.hpp
  • /ninjecture/node_modules/node-sass/src/sass_types/factory.cpp
  • /ninjecture/node_modules/node-sass/src/libsass/include/sass/functions.h
  • /ninjecture/node_modules/node-sass/src/callback_bridge.h
  • /ninjecture/node_modules/node-sass/src/sass_types/list.cpp

Vulnerability Details

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

Publish Date: 2018-06-04

URL: CVE-2018-11697

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here