Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2017-5656 Vulnerability in maven package org.apache.cxf:cxf-rt-ws-security
CVE-2015-9244 Vulnerability in npm package mysql
CVE-2021-28163 Vulnerability in maven package org.eclipse.jetty:jetty-deploy
CVE-2017-4974 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2022-24999 Vulnerability in maven package org.webjars.npm:qs