Description
unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/206
Related Vulnerabilities
CVE-2017-20165 Vulnerability in maven package org.webjars.npm:debug
CVE-2018-1288 Vulnerability in maven package org.apache.kafka:kafka
CVE-2021-32702 Vulnerability in npm package nextjs-auth0
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-41900 Vulnerability in maven package org.eclipse.jetty:jetty-openid