HIGH
Arbitrary Code Execution
Published Sep 3, 2020
7.1
HIGHCVSS 3.1
EPSS 2.30%
Description
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Affected products
- Vendor n/a Product Grunt Defaultn/a
- Version unspecifiedStatusaffectedConstraints<1.3.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Grunt | n/a |
|
Configuration 2
- 9.0
Configuration 3
- 18.04
No data.
No Red Hat product state for this CVE.
grunt
npm
Introduced 0 Fixed 1.3.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | grunt | 0 | 1.3.0 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-m5pj-vjjf-4m3h Advisory
- https://github.com/gruntjs/grunt/blob/master/lib/grunt/file.js%23L249 x_refsource_MISCBroken Link
- https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00008.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7729
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-607922 x_refsource_MISCThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-GRUNT-597546 x_refsource_MISCExploitThird Party Advisory
- https://usn.ubuntu.com/4595-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-m5pj-vjjf-4m3h | Advisory | |
| https://github.com/gruntjs/grunt/blob/master/lib/grunt/file.js%23L249 | x_refsource_MISCBroken Link | |
| https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7 | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/09/msg00008.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7729 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-607922 | x_refsource_MISCThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-GRUNT-597546 | x_refsource_MISCExploitThird Party Advisory | |
| https://usn.ubuntu.com/4595-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Sep 3, 2020
Updated Sep 17, 2024
Reserved Jan 21, 2020
Link CVE-2020-7729
CISA Vulnrichment
GHSA-M5PJ-VJJF-4M3H Updated n/a