UNIX symbolic link following in grunt - CVE-2022-1537

 

UNIX symbolic link following in grunt - CVE-2022-1537

Published: February 7, 2023


Vulnerability identifier: #VU72013
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1537
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to the GruntJS user's .bashrc file and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

grunt
Bitbucket Data Center
Ubuntu
grunt (Ubuntu package)

How to mitigate CVE-2022-1537

Install updates from vendor's website.

grunt - update to 1.5.3
Bitbucket Data Center - update to 10.3.2
grunt (Ubuntu package) - update to Ubuntu Pro

External References

Related Security Bulletins