Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01dzljLXJ2OTYtZnI3Z801FQ

Removal of functional code in faker.js

Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable. This is related to the colors.js CVE-2021-23567.

The functional code for this package was forked and can be found here.

Permalink: https://github.com/advisories/GHSA-5w9c-rv96-fr7g
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01dzljLXJ2OTYtZnI3Z801FQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: over 1 year ago


Identifiers: GHSA-5w9c-rv96-fr7g
References: Repository: https://github.com/Marak/colors.js
Blast Radius: 0.0

Affected Packages

npm:faker
Dependent packages: 5,968
Dependent repositories: 85,609
Downloads: 8,107,634 last month
Affected Version Ranges: = 6.6.6
No known fixed version
All affected versions: 6.6.6