Description
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/183
Related Vulnerabilities
CVE-2012-0394 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-14863 Vulnerability in maven package org.webjars.bower:angular
CVE-2020-7686 Vulnerability in npm package rollup-plugin-dev-server
CVE-2019-1010091 Vulnerability in maven package org.webjars.bower:tinymce
CVE-2021-21638 Vulnerability in maven package org.jenkins-ci.plugins:tfs