Description
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/234
Related Vulnerabilities
CVE-2020-1950 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2023-46497 Vulnerability in npm package @evershop/evershop
CVE-2022-25897 Vulnerability in maven package org.eclipse.milo:sdk-server
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2023-39410 Vulnerability in maven package org.apache.avro:avro