Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2021-45459 Vulnerability in npm package node-windows
CVE-2022-32210 Vulnerability in npm package undici
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-2120 Vulnerability in maven package org.jenkins-ci.plugins:fitnesse