Description
sfml downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/256
Related Vulnerabilities
CVE-2020-28282 Vulnerability in npm package getobject
CVE-2019-10402 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10389 Vulnerability in maven package org.jenkins-ci.plugins:relution-publisher
CVE-2013-2135 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2018-8034 Vulnerability in maven package org.apache.tomcat:tomcat-websocket