Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2022-21718 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-10790 Vulnerability in npm package taffy
CVE-2022-36036 Vulnerability in npm package mdx-mermaid
CVE-2020-27223 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2022-36083 Vulnerability in maven package org.webjars.npm:jose