Description
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/183
Related Vulnerabilities
CVE-2018-16131 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.11
CVE-2021-28092 Vulnerability in maven package org.webjars:is-svg
CVE-2020-2252 Vulnerability in maven package org.jenkins-ci.plugins:mailer
CVE-2020-7656 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2021-21181 Vulnerability in maven package org.webjars.npm:electron