Description
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/211
Related Vulnerabilities
CVE-2017-5649 Vulnerability in maven package org.apache.geode:geode-pulse
CVE-2019-19899 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2020-25638 Vulnerability in maven package org.hibernate:hibernate-core
CVE-2017-17068 Vulnerability in npm package auth0-js
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js