Skip to content

Removal of functional code in faker.js

High severity GitHub Reviewed Published Mar 22, 2022 to the GitHub Advisory Database • Updated Jan 11, 2023

Package

npm faker (npm)

Affected versions

= 6.6.6

Patched versions

None

Description

Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable. This is related to the colors.js CVE-2021-23567.

The functional code for this package was forked and can be found here.

References

Published to the GitHub Advisory Database Mar 22, 2022
Reviewed Mar 22, 2022
Last updated Jan 11, 2023

Severity

High

EPSS score

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-5w9c-rv96-fr7g

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.