Known vulnerabilities in grunt
Vendor:
gruntjs
Software:
grunt
Software CPE:
cpe:2.3:a:gruntjs:grunt:*:*:*:*:*:*:*:*
Website:
https://gruntjs.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.6.1
1.6.0
1.5.3
1.5.2
1.5.1
1.5.0
1.4.1
1.4.0
1.3.0
1.2.1
1.2.0
1.1.0
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
0.4.5
0.4.4
0.4.3
0.4.2
0.4.1
0.4.0
0.3.17
0.3.16
0.3.15
0.3.14
0.3.13
0.3.12
0.3.11
0.3.10
0.3.9
0.3.8
0.3.7
0.3.6
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.15
0.2.14
0.2.13
0.2.12
0.2.11
0.2.10
0.2.9
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.2
0.1.1
0.1.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU72013 - UNIX Symbolic Link (Symlink) Following CVE-2022-1537 |
CWE-61 | Low | 1.5.3 | 07.02.2023 |
SB2023020752 SB2023020757 SB2026072615 |
||
| #VU72012 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-0436 |
CWE-22 | Medium | 1.5.2 | 07.02.2023 |
SB2023020751 SB2023020757 SB2022051189 |
||
| #VU46068 - Improper Control of Generation of Code ('Code Injection') CVE-2020-7729 |
CWE-94 | Medium | 1.3.0 | 26.08.2020 |
SB2020082603 SB2023020757 SB2022030731 and 3 more |