First published: Tue Apr 23 2019(Updated: )
LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | =3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20822.
The severity of CVE-2018-20822 is medium with a CVSS severity score of 6.5.
CVE-2018-20822 allows attackers to cause a denial-of-service through uncontrolled recursion in Sass::Complex_Selector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp.
Version 3.5.4 of LibSass is affected by CVE-2018-20822.
Yes, there is a fix available for CVE-2018-20822. It is recommended to update to a version of LibSass that is not affected by this vulnerability.