Description
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Remediation
References
https://nodesecurity.io/advisories/249
Related Vulnerabilities
CVE-2019-10759 Vulnerability in npm package safer-eval
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2019-10416 Vulnerability in maven package org.jenkins-ci.plugins:violation-comments-to-gitlab
CVE-2016-10661 Vulnerability in npm package phantomjs-cheniu
CVE-2021-29445 Vulnerability in npm package jose-node-esm-runtime