Description
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/234
Related Vulnerabilities
CVE-2021-27644 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server
CVE-2016-10668 Vulnerability in npm package libsbml
CVE-2018-11039 Vulnerability in maven package org.springframework:spring-web
CVE-2017-12974 Vulnerability in maven package com.nimbusds:nimbus-jose-jwt
CVE-2017-7545 Vulnerability in maven package org.jbpm:jbpm-designer-backend