tiny-json-http@5.2.0

Vulnerabilities

1 via 1 paths

Dependencies

Source

npm

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

medium severity

Man-in-the-Middle (MitM)

  • Vulnerable module: tiny-json-http
  • Introduced through: tiny-json-http@5.2.0

Detailed paths

  • Introduced through: tiny-json-http@5.2.0
    Remediation: Upgrade to tiny-json-http@7.0.0.

Overview

tiny-json-http is a minimalist HTTP client for GET and POSTing JSON payloads.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM) attacks. It contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.

Remediation

Upgrade tiny-json-http to version 7.0.0 or higher.

References