Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2017-1000190 Vulnerability in maven package org.simpleframework:simple-xml
CVE-2022-31194 Vulnerability in maven package org.dspace:dspace-jspui
CVE-2018-1000013 Vulnerability in maven package org.jenkins-ci.plugins:release
CVE-2022-43402 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps