Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2021-32641 Vulnerability in npm package auth0-lock
CVE-2020-7720 Vulnerability in npm package node-forge
CVE-2016-10627 Vulnerability in npm package scala-bin
CVE-2022-24802 Vulnerability in npm package deepmerge-ts
CVE-2019-10305 Vulnerability in maven package com.xebialabs.xl-deploy:jenkins-dependendencies