Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/188
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
Related Vulnerabilities
CVE-2015-8854 Vulnerability in maven package org.webjars:marked
CVE-2017-16194 Vulnerability in npm package picard
CVE-2018-1000408 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-23630 Vulnerability in npm package eta
CVE-2022-31170 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable