Description
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/234
Related Vulnerabilities
CVE-2020-2280 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2023-35141 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-15599 Vulnerability in npm package treekill
CVE-2015-9244 Vulnerability in npm package mysql
CVE-2022-34305 Vulnerability in maven package org.apache.tomcat:tomcat