Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/188
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
Related Vulnerabilities
CVE-2019-12406 Vulnerability in maven package org.apache.cxf:cxf-core
CVE-2021-26272 Vulnerability in npm package ckeditor4-dev
CVE-2021-32732 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2022-23618 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore