Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2022-45392 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2022-1295 Vulnerability in maven package org.webjars.bower:fullpage
CVE-2017-18349 Vulnerability in maven package com.alibaba:fastjson
CVE-2016-11023 Vulnerability in maven package org.odata4j:odata4j-core