Description
sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/256
Related Vulnerabilities
CVE-2013-4170 Vulnerability in npm package ember
CVE-2022-23913 Vulnerability in maven package org.apache.activemq:artemis-commons
CVE-2023-33695 Vulnerability in maven package cn.hutool:hutool-core
CVE-2022-1245 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2019-13173 Vulnerability in maven package org.webjars:fstream