Description
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/211
Related Vulnerabilities
CVE-2021-21166 Vulnerability in npm package electron
CVE-2019-17359 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2022-43405 Vulnerability in maven package io.jenkins.plugins:pipeline-groovy-lib
CVE-2021-29445 Vulnerability in npm package jose-node-esm-runtime
CVE-2020-11612 Vulnerability in maven package io.netty:netty-codec