Description
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/161
Related Vulnerabilities
CVE-2019-10364 Vulnerability in maven package org.jenkins-ci.plugins:ec2
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15to18
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2022-1245 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-7684 Vulnerability in npm package rollup-plugin-serve-favicon