pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2019-0360 | pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulnerable to MITM attacks. | 
  Github GHSA | 
                GHSA-x3j8-g4v9-67jq | Downloads Resources over HTTP in pennyworth | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://nodesecurity.io/advisories/213 | 
                     | 
            
History
                    No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T00:56:48.996Z
Reserved: 2017-10-29T00:00:00
Link: CVE-2016-10619
No data.
Status : Modified
Published: 2018-06-01T18:29:01.863
Modified: 2024-11-21T02:44:23.203
Link: CVE-2016-10619
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA