Description
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/197
Related Vulnerabilities
CVE-2020-15130 Vulnerability in npm package slpjs
CVE-2021-4329 Vulnerability in npm package json-logic-js
CVE-2021-43309 Vulnerability in npm package uri-template-lite
CVE-2020-2240 Vulnerability in maven package org.jenkins-ci.plugins:database
CVE-2018-5673 Vulnerability in maven package org.apache.geronimo.plugins:dojo