Description
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/197
Related Vulnerabilities
CVE-2017-4960 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2020-7637 Vulnerability in npm package class-transformer
CVE-2016-10657 Vulnerability in npm package co-cli-installer
CVE-2023-31716 Vulnerability in npm package @frangoteam/fuxa