Description
pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/213
Related Vulnerabilities
CVE-2019-10329 Vulnerability in maven package org.jenkins-ci.plugins:influxdb
CVE-2015-5255 Vulnerability in maven package org.apache.flex.blazeds:flex-messaging-core
CVE-2020-8203 Vulnerability in npm package @sailshq/lodash
CVE-2017-16015 Vulnerability in npm package forms
CVE-2023-39156 Vulnerability in maven package org.jenkins-ci.plugins:bazaar