Description
nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
Remediation
References
https://nodesecurity.io/advisories/166
Related Vulnerabilities
CVE-2018-15494 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox
CVE-2018-3729 Vulnerability in npm package localhost-now
CVE-2020-28482 Vulnerability in npm package fastify-csrf
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2019-6002 Vulnerability in maven package com.linecorp.centraldogma:centraldogma-server