Lucene search

K

Colors.js Project Security Vulnerabilities

cve
cve

CVE-2021-23567

The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unfortunately this appears to have been a purposeful attempt by a maintainer of colors to make the package unusable, other maintainers' controls over thi...

7.5CVSS

7.5AI Score

0.004EPSS

2022-01-14 08:15 PM
36