Description
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/161
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror
CVE-2016-10707 Vulnerability in npm package jquery
CVE-2021-21179 Vulnerability in npm package electron
CVE-2020-2259 Vulnerability in maven package org.jenkins-ci.plugins:computer-queue-plugin
CVE-2018-1000822 Vulnerability in maven package org.codelibs.fess:fess