Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2021-21120 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-1295 Vulnerability in npm package fullpage.js
CVE-2018-11775 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2022-3423 Vulnerability in npm package nocodb
CVE-2022-36437 Vulnerability in maven package com.hazelcast.jet:hazelcast-jet-enterprise