vulnerability
Ubuntu: (Multiple Advisories) (CVE-2020-7729): Grunt vulnerability
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:H/Au:S/C:P/I:P/A:P) | Sep 3, 2020 | Oct 21, 2020 | Nov 15, 2024 |
Severity
5
CVSS
(AV:N/AC:H/Au:S/C:P/I:P/A:P)
Published
Sep 3, 2020
Added
Oct 21, 2020
Modified
Nov 15, 2024
Description
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Solution
ubuntu-pro-upgrade-grunt

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.