cbcvebase.
CVE-2022-1537
published 2022-05-10

CVE-2022-1537: file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3…

PriorityP336high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.30%
22.2th percentile
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiangrunt< grunt 1.5.3-1 (bookworm)grunt 1.5.3-1 (bookworm)
gruntjsgrunt< 1.5.31.5.3
gruntjsgrunt>= 0 < 1.3.0-1+deb11u21.3.0-1+deb11u2
gruntjsgrunt>= 0 < 1.5.3-11.5.3-1
gruntjsgrunt>= 0 < 1.5.3-11.5.3-1
gruntjsgrunt>= 0 < 1.5.3-11.5.3-1
gruntjsgrunt>= 0 < 1.0.1-8ubuntu0.1+esm11.0.1-8ubuntu0.1+esm1
gruntjsgrunt>= 0 < 1.0.4-2ubuntu0.1~esm11.0.4-2ubuntu0.1~esm1
gruntjsgrunt>= 0 < 1.4.1-2ubuntu0.1~esm11.4.1-2ubuntu0.1~esm1
gruntjsgrunt>= 0 < 1.5.31.5.3
gruntjsgruntjs_grunt>= unspecified < 1.5.31.5.3

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.