Description
geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/183
Related Vulnerabilities
CVE-2019-16728 Vulnerability in npm package dompurify
CVE-2019-10316 Vulnerability in maven package org.jenkins-ci.plugins:aqua-microscanner
CVE-2016-4055 Vulnerability in maven package org.webjars.bower:moment
CVE-2021-39149 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-1003075 Vulnerability in maven package org.jenkins-ci.plugins:audit2db