Description
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/161
Related Vulnerabilities
CVE-2016-10538 Vulnerability in npm package cli
CVE-2020-35214 Vulnerability in maven package io.atomix:atomix
CVE-2019-1010266 Vulnerability in maven package org.webjars.npm:lodash
CVE-2018-16492 Vulnerability in npm package extend
CVE-2021-33605 Vulnerability in maven package com.vaadin:vaadin-checkbox-flow