Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2020-28442 Vulnerability in npm package js-data
CVE-2019-1003091 Vulnerability in maven package com.soasta.jenkins:cloudtest
CVE-2021-43309 Vulnerability in npm package uri-template-lite
CVE-2016-10550 Vulnerability in npm package sequelize
CVE-2017-7525 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind