Description
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/249
Related Vulnerabilities
CVE-2023-39155 Vulnerability in maven package org.jenkins-ci.plugins:chef-identity
CVE-2017-7545 Vulnerability in maven package org.jbpm:jbpm-designer-backend
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.gce
CVE-2020-36650 Vulnerability in npm package gry
CVE-2022-40309 Vulnerability in maven package org.apache.archiva:maven2-repository