Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2020-29204 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2020-7762 Vulnerability in npm package jsreport-chrome-pdf
CVE-2020-7760 Vulnerability in npm package codemirror
CVE-2016-1000232 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2023-37958 Vulnerability in maven package org.jenkins-ci.plugins:sumologic-publisher