Description
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/228
Related Vulnerabilities
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2022-0839 Vulnerability in maven package org.liquibase:liquibase-core
CVE-2020-8840 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind