Update dependency grunt to v1.5.3 [SECURITY]#52
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
7ccd522 to
17d56fc
Compare
17d56fc to
9ca7e81
Compare
9ca7e81 to
12a8530
Compare
12a8530 to
f83be41
Compare
f83be41 to
8b1f2d3
Compare
8b1f2d3 to
c09e0d6
Compare
c09e0d6 to
c02f420
Compare
c02f420 to
7476b57
Compare
7476b57 to
a7be8e9
Compare
a7be8e9 to
ef03798
Compare
ef03798 to
e1d23a7
Compare
e1d23a7 to
84f66c2
Compare
84f66c2 to
49b3cba
Compare
49b3cba to
6c6014f
Compare
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
6c6014f to
49b3cba
Compare
49b3cba to
1b79a2e
Compare
1b79a2e to
209cea3
Compare
209cea3 to
49b3cba
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.4.1→1.5.3Path Traversal in Grunt
CVE-2022-0436 / GHSA-j383-35pm-c5h4
More information
Details
Grunt prior to version 1.5.2 is vulnerable to path traversal.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Race Condition in Grunt
CVE-2022-1537 / GHSA-rm36-94g8-835r
More information
Details
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.
Severity
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
gruntjs/grunt (grunt)
v1.5.3Compare Source
572d79b58016ff0749e1d69b7c50v1.5.2Compare Source
7f15fd5b0ec6e1433f91bv1.5.1Compare Source
ad226080652305v1.5.0Compare Source
b2b2c2b3eda6ae47d32de2e9161c04b960eaad3d45fdc7056e35fe54Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.