Description
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/249
Related Vulnerabilities
CVE-2020-28271 Vulnerability in npm package deephas
CVE-2022-31112 Vulnerability in npm package parse-server
CVE-2021-40525 Vulnerability in maven package org.apache.james:james-server
CVE-2022-31198 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2022-24709 Vulnerability in npm package @awsui/components-react