Description
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/197
Related Vulnerabilities
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-rt-core
CVE-2020-7639 Vulnerability in npm package eivindfjeldstad-dot
CVE-2016-4432 Vulnerability in maven package org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol
CVE-2018-5158 Vulnerability in maven package org.webjars.bowergithub.mozilla:pdfjs-dist
CVE-2017-1000085 Vulnerability in maven package org.jenkins-ci.plugins:subversion