Description
prebuild-lwip is a module for comprehensive, fast, and simple image processing and manipulation. prebuild-lwip downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/248
Related Vulnerabilities
CVE-2023-46298 Vulnerability in npm package next
CVE-2022-4640 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-46502 Vulnerability in maven package org.opencrx:opencrx-core
CVE-2022-31170 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2019-10428 Vulnerability in maven package org.jenkins-ci.plugins:aqua-security-scanner