Description
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/249
Related Vulnerabilities
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2023-34614 Vulnerability in maven package cc.plural:jsonij
CVE-2023-37962 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator
CVE-2019-10753 Vulnerability in maven package com.diffplug.spotless:spotless-eclipse-wtp