GHSA-5w9c-rv96-fr7g

Suggest an improvement
Source
https://github.com/advisories/GHSA-5w9c-rv96-fr7g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-5w9c-rv96-fr7g/GHSA-5w9c-rv96-fr7g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5w9c-rv96-fr7g
Published
2022-03-22T19:28:24Z
Modified
2022-03-22T20:33:40Z
Summary
Removal of functional code in faker.js
Details

Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable. This is related to the colors.js CVE-2021-23567.

The functional code for this package was forked and can be found here.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-03-22T19:28:24Z"
}
References

Affected packages

npm / faker

Package

Affected ranges

Affected versions

6.*

6.6.6