QID 982660
QID 982660: Nodejs (npm) Security Update for grunt (GHSA-m5pj-vjjf-4m3h)
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m5pj-vjjf-4m3h for updates pertaining to this vulnerability.
Vendor References
- GHSA-m5pj-vjjf-4m3h -
github.com/advisories/GHSA-m5pj-vjjf-4m3h
CVEs related to QID 982660
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m5pj-vjjf-4m3h | grunt |
|