Lucene search

K

Grunt Security Vulnerabilities

cve
cve

CVE-2020-7729

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

7.1CVSS

6.8AI Score

0.009EPSS

2020-09-03 09:15 AM
59
4
cve
cve

CVE-2022-0436

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

5.5CVSS

5.5AI Score

0.001EPSS

2022-04-12 09:15 PM
69
cve
cve

CVE-2022-1537

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged ...

7CVSS

6.9AI Score

0.0004EPSS

2022-05-10 02:15 PM
72
4