Description
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/228
Related Vulnerabilities
CVE-2016-6797 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-10384 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-1010266 Vulnerability in maven package org.webjars.npm:lodash
CVE-2023-32261 Vulnerability in maven package org.jenkins-ci.plugins:dimensionsscm