Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
https://nodesecurity.io/advisories/188
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package bip30
CVE-2021-21292 Vulnerability in maven package org.traccar:traccar
CVE-2016-6802 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2018-16131 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.11
CVE-2020-11002 Vulnerability in maven package io.dropwizard:dropwizard-validation