Description
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/183
Related Vulnerabilities
CVE-2019-10463 Vulnerability in maven package org.jenkins-ci.plugins:dynatrace-dashboard
CVE-2020-15130 Vulnerability in npm package slpjs
CVE-2020-23811 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js
CVE-2023-34189 Vulnerability in maven package org.apache.inlong:manager-web