Description
sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/256
Related Vulnerabilities
CVE-2019-16761 Vulnerability in npm package slp-validate
CVE-2020-2293 Vulnerability in maven package org.jenkins-ci.plugins:persona
CVE-2018-1000173 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2018-1282 Vulnerability in maven package org.apache.hive:hive-jdbc
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client