Description
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/234
Related Vulnerabilities
CVE-2021-23399 Vulnerability in npm package wincred
CVE-2022-2421 Vulnerability in npm package socket.io-parser
CVE-2020-10244 Vulnerability in maven package dev.paseto:jpaseto-impl
CVE-2019-1010266 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2017-2602 Vulnerability in maven package org.jenkins-ci.main:jenkins-core