Description
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/161
Related Vulnerabilities
CVE-2016-10587 Vulnerability in npm package wasdk
CVE-2019-16556 Vulnerability in maven package org.jenkins-ci.plugins:rundeck
CVE-2020-2269 Vulnerability in maven package org.jenkins-ci.plugins:chosen-views-tabbar
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.ihc
CVE-2020-13949 Vulnerability in maven package org.apache.thrift:libthrift