cbcvebase.
CVE-2022-0436
published 2022-04-12

CVE-2022-0436: Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.57%
43.4th percentile
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiangrunt< grunt 1.5.2-2 (bookworm)grunt 1.5.2-2 (bookworm)
gruntjsgrunt< 1.5.21.5.2
gruntjsgrunt>= 0 < 1.3.0-1+deb11u11.3.0-1+deb11u1
gruntjsgrunt>= 0 < 1.5.2-21.5.2-2
gruntjsgrunt>= 0 < 1.5.2-21.5.2-2
gruntjsgrunt>= 0 < 1.5.2-21.5.2-2
gruntjsgrunt>= 0 < 1.0.1-8ubuntu0.1+esm11.0.1-8ubuntu0.1+esm1
gruntjsgrunt>= 0 < 1.0.4-2ubuntu0.1~esm11.0.4-2ubuntu0.1~esm1
gruntjsgrunt>= 0 < 1.4.1-2ubuntu0.1~esm11.4.1-2ubuntu0.1~esm1
gruntjsgrunt>= 0 < 1.5.21.5.2
gruntjsgruntjs_grunt>= unspecified < 1.5.21.5.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.