Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2021-25916 Vulnerability in npm package patchmerge
CVE-2019-19771 Vulnerability in npm package lodahs
CVE-2020-26237 Vulnerability in maven package org.webjars.npm:highlight.js
CVE-2018-1306 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo
CVE-2018-20676 Vulnerability in maven package org.webjars.bower:bootstrap