Description
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/228
Related Vulnerabilities
CVE-2015-0254 Vulnerability in maven package javax.servlet:jstl
CVE-2019-9212 Vulnerability in maven package com.alipay.sofa:hessian
CVE-2023-26487 Vulnerability in npm package vega-functions
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp