Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
https://nodesecurity.io/advisories/188
Related Vulnerabilities
CVE-2022-25168 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2023-22467 Vulnerability in maven package org.webjars.bowergithub.moment:luxon
CVE-2016-10645 Vulnerability in npm package grunt-images
CVE-2016-4438 Vulnerability in maven package org.apache.struts:struts2-rest-plugin