PT-2022-28175 · Npm · Coloros
Published
2022-01-12
·
Updated
2022-01-12
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
colors package versions prior to 0.26.1
Description
The vulnerability is related to the
colors package, which caused zalgo-like output, breaking servers. Only NPM users who recently upgraded or installed the NPM package are affected. Docker users seem not to be affected as the dependencies were bundled at the time of the build.Recommendations
For versions prior to 0.26.1, upgrade to the latest patch, version 0.26.1, to resolve the issue.
As a temporary workaround, consider avoiding the use of the
colors package until the issue is resolved. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coloros