## CVE-2022-25758 - High Severity Vulnerability Vulnerable Library - scss-tokenizer-0.2.3.tgz A tokenzier for Sass' SCSS syntax Library home page: https://registry.npmjs.org/scss-tokenizer/-/scss-tokenizer-0.2.3.tgz Dependency Hierarchy: - @osd/ui-framework-1.0.0.tgz (Root Library) - node-sass-6.0.1.tgz - sass-graph-2.2.5.tgz - :x: **scss-tokenizer-0.2.3.tgz** (Vulnerable Library) Found in base branch: main Vulnerability Details All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex. Publish Date: 2022-07-01 URL: CVE-2022-25758 CVSS 3 Score Details (7.5) Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High For more information on CVSS3 Scores, click here. Suggested Fix Type: Upgrade version Origin: https://nvd.nist.gov/vuln/detail/CVE-2022-25758 Release Date: 2022-07-01 Fix Resolution: no_fix