Description
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/228
Related Vulnerabilities
CVE-2022-4245 Vulnerability in maven package org.codehaus.plexus:plexus-utils
CVE-2020-7627 Vulnerability in npm package node-key-sender
CVE-2011-2487 Vulnerability in maven package org.apache.ws.security:wss4j
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-lite
CVE-2018-16330 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md