Логотип exploitDog
bind:CVE-2022-1537
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1537

Количество 5

Количество 5

ubuntu логотип

CVE-2022-1537

больше 3 лет назад

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-1537

больше 3 лет назад

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-1537

больше 3 лет назад

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2022-1537

больше 3 лет назад

file.copy operations in GruntJS are vulnerable to a TOCTOU race condit ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-rm36-94g8-835r

больше 3 лет назад

Race Condition in Grunt

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-1537

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-1537

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-1537

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

CVSS3: 7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-1537

file.copy operations in GruntJS are vulnerable to a TOCTOU race condit ...

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-rm36-94g8-835r

Race Condition in Grunt

CVSS3: 7
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу