Description
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/211
Related Vulnerabilities
CVE-2019-5485 Vulnerability in npm package gitlabhook
CVE-2018-16487 Vulnerability in maven package org.webjars:lodash
CVE-2018-1000006 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-2199 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2017-10355 Vulnerability in maven package xerces:xercesimpl