Versions of redbird prior to 0.9.1 have a vulnerable default configuration of allowing TLS 1.0 connections on lib/proxy.js. The package does not provide an option to disable TLS 1.0 which is deprecated and vulnerable.
Upgrade to version 0.9.1 or later.
{
"github_reviewed": true,
"github_reviewed_at": "2019-06-06T13:06:37Z",
"nvd_published_at": null,
"severity": "MODERATE",
"cwe_ids": [
"CWE-20"
]
}