Description
sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/256
Related Vulnerabilities
CVE-2014-3600 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2021-23376 Vulnerability in npm package ffmpegdotjs
CVE-2023-1370 Vulnerability in maven package net.minidev:json-smart
CVE-2019-16767 Vulnerability in npm package ezmaster
CVE-2023-46650 Vulnerability in maven package com.coravy.hudson.plugins.github:github