Gruntjs Grunt vulnerabilities
2 known vulnerabilities affecting gruntjs/gruntjs_grunt.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-1537HIGHCVSS 7.0≥ unspecified, < 1.5.32022-05-10
CVE-2022-1537 [HIGH] CWE-367 CVE-2022-1537: file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination dire
cvelistv5nvd
CVE-2022-0436MEDIUMCVSS 5.5≥ unspecified, < 1.5.22022-04-12
CVE-2022-0436 [MEDIUM] CWE-22 CVE-2022-0436: Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
cvelistv5nvd