CVE-2020-7729
published 2020-09-03CVE-2020-7729: The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement…
PriorityP336high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
EPSS
2.28%
81.2th percentile
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | grunt | < grunt 1.3.0-1 (bookworm) | grunt 1.3.0-1 (bookworm) |
| gruntjs | grunt | < 1.3.0 | 1.3.0 |
| gruntjs | grunt | >= 0 < 1.3.0-1 | 1.3.0-1 |
| gruntjs | grunt | >= 0 < 1.3.0-1 | 1.3.0-1 |
| gruntjs | grunt | >= 0 < 1.3.0-1 | 1.3.0-1 |
| gruntjs | grunt | >= 0 < 1.3.0-1 | 1.3.0-1 |
| gruntjs | grunt | >= 0 < 1.0.1-8ubuntu0.1 | 1.0.1-8ubuntu0.1 |
| gruntjs | grunt | >= 0 < 1.0.1-8ubuntu0.1+esm1 | 1.0.1-8ubuntu0.1+esm1 |
| gruntjs | grunt | >= 0 < 1.0.4-2ubuntu0.1~esm1 | 1.0.4-2ubuntu0.1~esm1 |
| gruntjs | grunt | >= 0 < 1.4.1-2ubuntu0.1~esm1 | 1.4.1-2ubuntu0.1~esm1 |
| gruntjs | grunt | >= 0 < 1.3.0 | 1.3.0 |
| gruntjs | grunt | >= unspecified < 1.3.0 | 1.3.0 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Grunt vulnerabilities
vendor_ubuntu·2023-02-07·CVSS 7.1
CVE-2020-7729 [HIGH] Grunt vulnerabilities
Title: Grunt vulnerabilities
Summary: Several security issues were fixed in Grunt.
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
Instructions: In general, a standard system update wi
Ubuntu
Grunt vulnerability
vendor_ubuntu·2020-10-20·CVSS 7.1
CVE-2020-7729 [HIGH] Grunt vulnerability
Title: Grunt vulnerability
Summary: Grunt could be made to run programs if it received specially crafted
input.
It was discovered that Grunt did not properly load yaml files. An attacker
could possibly use this to execute arbitrary code. (CVE-2020-7729)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-7729: grunt - The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to...
vendor_debian·2020·CVSS 7.1
CVE-2020-7729 [HIGH] CVE-2020-7729: grunt - The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to...
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Scope: local
bookworm: resolved (fixed in 1.3.0-1)
bullseye: resolved (fixed in 1.3.0-1)
forky: resolved (fixed in 1.3.0-1)
sid: resolved (fixed in 1.3.0-1)
trixie: resolved (fixed in 1.3.0-1)
OSV
grunt vulnerabilities
osv·2023-02-07·CVSS 7.1
CVE-2020-7729 [HIGH] grunt vulnerabilities
grunt vulnerabilities
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
GHSA
Arbitrary Code Execution in grunt
ghsa·2021-05-06
CVE-2020-7729 [HIGH] CWE-1188 Arbitrary Code Execution in grunt
Arbitrary Code Execution in grunt
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
OSV
Arbitrary Code Execution in grunt
osv·2021-05-06
CVE-2020-7729 [HIGH] Arbitrary Code Execution in grunt
Arbitrary Code Execution in grunt
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
OSV
grunt vulnerability
osv·2020-10-20·CVSS 7.1
CVE-2020-7729 [HIGH] grunt vulnerability
grunt vulnerability
It was discovered that Grunt did not properly load yaml files. An attacker
could possibly use this to execute arbitrary code. (CVE-2020-7729)
OSV
CVE-2020-7729: The package grunt before 1
osv·2020-09-03·CVSS 7.1
CVE-2020-7729 [HIGH] CVE-2020-7729: The package grunt before 1
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [fedora-all]
bugzilla·2020-09-03·CVSS 7.1
CVE-2020-7729 [HIGH] CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [fedora-all]
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [epel-all]
bugzilla·2020-09-03·CVSS 7.1
CVE-2020-7729 [HIGH] CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [epel-all]
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE
bugzilla·2020-09-03·CVSS 7.1
CVE-2020-7729 [HIGH] CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE
CVE-2020-7729 nodejs-grunt: use of the unsafe load function from js-yaml package can lead to ACE
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Reference:
https://snyk.io/vuln/SNYK-JS-GRUNT-597546
Upstream commit:
https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7
Discussion:
Created nodejs-grunt tracking bugs for this issue:
Affects: epel-all [bug 1875432]
Affects: fedora-all [bug 1875431]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status
https://github.com/gruntjs/grunt/blob/master/lib/grunt/file.js%23L249https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7https://lists.debian.org/debian-lts-announce/2020/09/msg00008.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-607922https://snyk.io/vuln/SNYK-JS-GRUNT-597546https://usn.ubuntu.com/4595-1/https://github.com/gruntjs/grunt/blob/master/lib/grunt/file.js%23L249https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7https://lists.debian.org/debian-lts-announce/2020/09/msg00008.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-607922https://snyk.io/vuln/SNYK-JS-GRUNT-597546https://usn.ubuntu.com/4595-1/
2020-09-03
Published