Description
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/197
Related Vulnerabilities
CVE-2019-16869 Vulnerability in maven package io.netty:netty-all
CVE-2022-41777 Vulnerability in npm package nadesiko3
CVE-2020-28278 Vulnerability in npm package shvl
CVE-2021-27515 Vulnerability in maven package org.webjars.bowergithub.unshiftio:url-parse
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http