CVE-2022-0436
published 2022-04-12CVE-2022-0436: Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.57%
43.4th percentile
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grunt | < grunt 1.5.2-2 (bookworm) | grunt 1.5.2-2 (bookworm) |
| gruntjs | grunt | < 1.5.2 | 1.5.2 |
| gruntjs | grunt | >= 0 < 1.3.0-1+deb11u1 | 1.3.0-1+deb11u1 |
| gruntjs | grunt | >= 0 < 1.5.2-2 | 1.5.2-2 |
| gruntjs | grunt | >= 0 < 1.5.2-2 | 1.5.2-2 |
| gruntjs | grunt | >= 0 < 1.5.2-2 | 1.5.2-2 |
| gruntjs | grunt | >= 0 < 1.0.1-8ubuntu0.1+esm1 | 1.0.1-8ubuntu0.1+esm1 |
| gruntjs | grunt | >= 0 < 1.0.4-2ubuntu0.1~esm1 | 1.0.4-2ubuntu0.1~esm1 |
| gruntjs | grunt | >= 0 < 1.4.1-2ubuntu0.1~esm1 | 1.4.1-2ubuntu0.1~esm1 |
| gruntjs | grunt | >= 0 < 1.5.2 | 1.5.2 |
| gruntjs | gruntjs_grunt | >= unspecified < 1.5.2 | 1.5.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
grunt vulnerabilities
osv·2023-02-07·CVSS 7.1
CVE-2020-7729 [HIGH] grunt vulnerabilities
grunt vulnerabilities
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
GHSA
Path Traversal in Grunt
ghsa·2022-04-13
CVE-2022-0436 [MEDIUM] CWE-22 Path Traversal in Grunt
Path Traversal in Grunt
Grunt prior to version 1.5.2 is vulnerable to path traversal.
OSV
Path Traversal in Grunt
osv·2022-04-13
CVE-2022-0436 [MEDIUM] Path Traversal in Grunt
Path Traversal in Grunt
Grunt prior to version 1.5.2 is vulnerable to path traversal.
OSV
CVE-2022-0436: Path Traversal in GitHub repository gruntjs/grunt prior to 1
osv·2022-04-12·CVSS 5.5
CVE-2022-0436 [MEDIUM] CVE-2022-0436: Path Traversal in GitHub repository gruntjs/grunt prior to 1
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Ubuntu
Grunt vulnerabilities
vendor_ubuntu·2023-02-07·CVSS 7.1
CVE-2020-7729 [HIGH] Grunt vulnerabilities
Title: Grunt vulnerabilities
Summary: Several security issues were fixed in Grunt.
It was discovered that Grunt was not properly loading YAML files before
parsing them. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-7729)
It was discovered that Grunt was not properly handling symbolic links
when performing file copy operations. An attacker could possibly use this
issue to expose sensitive information or execute arbitrary code.
(CVE-2022-0436)
It was discovered that there was a race condition in the Grunt file copy
function, which could lead to an arbitrary file write. An attacker could
possibly use this issue to perform a local privilege escalation attack or
to execute arbitrary code. (CVE-2022-1537)
Instructions: In general, a standard system update wi
Debian
CVE-2022-0436: grunt - Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
vendor_debian·2022·CVSS 5.5
CVE-2022-0436 [MEDIUM] CVE-2022-0436: grunt - Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Scope: local
bookworm: resolved (fixed in 1.5.2-2)
bullseye: resolved (fixed in 1.3.0-1+deb11u1)
forky: resolved (fixed in 1.5.2-2)
sid: resolved (fixed in 1.5.2-2)
trixie: resolved (fixed in 1.5.2-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gruntjs/grunt/commit/aad3d4521c3098fb255fb2db8f2e1d691a033665https://huntr.dev/bounties/f55315e9-9f6d-4dbb-8c40-bae50c1ae92bhttps://lists.debian.org/debian-lts-announce/2023/04/msg00008.htmlhttps://github.com/gruntjs/grunt/commit/aad3d4521c3098fb255fb2db8f2e1d691a033665https://huntr.dev/bounties/f55315e9-9f6d-4dbb-8c40-bae50c1ae92bhttps://lists.debian.org/debian-lts-announce/2023/04/msg00008.html
2022-04-12
Published