Description
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/197
Related Vulnerabilities
CVE-2017-7664 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2021-21413 Vulnerability in npm package isolated-vm
CVE-2019-1003097 Vulnerability in maven package com.ds.tools.hudson:crowd
CVE-2019-10346 Vulnerability in maven package org.jenkins-ci.plugins:embeddable-build-status