Description
jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://github.com/jser/stat-js/blob/master/data/url-mapping.js
https://nodesecurity.io/advisories/188
Related Vulnerabilities
CVE-2017-8045 Vulnerability in maven package org.springframework.amqp:spring-amqp
CVE-2016-10596 Vulnerability in npm package imageoptim
CVE-2017-5641 Vulnerability in maven package com.adobe.blazeds:flex-messaging-core
CVE-2017-7665 Vulnerability in maven package org.apache.nifi:nifi
CVE-2017-5650 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core