Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
https://nodesecurity.io/advisories/188
Related Vulnerabilities
CVE-2022-24847 Vulnerability in maven package org.geoserver:gs-main
CVE-2020-7681 Vulnerability in npm package marscode
CVE-2017-2582 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2012-0393 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-8897 Vulnerability in maven package com.amazonaws:aws-encryption-sdk-java