Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
https://nodesecurity.io/advisories/188
Related Vulnerabilities
CVE-2022-31195 Vulnerability in maven package org.dspace:dspace-api
CVE-2020-26289 Vulnerability in npm package date-and-time
CVE-2016-10546 Vulnerability in npm package pouchdb
CVE-2021-29060 Vulnerability in npm package color-string
CVE-2021-27582 Vulnerability in maven package org.mitre:openid-connect-server