ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
The product does not encrypt sensitive or critical information before storage or transmission.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/249 | third party advisory |