7.1
CVSSv3

CVE-2020-7729

Published: 03/09/2020 Updated: 16/11/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 410
Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P

Vulnerability Summary

The package grunt prior to 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gruntjs grunt

debian debian linux 9.0

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #969668 grunt: CVE-2020-7729 Package: src:grunt; Maintainer for src:grunt is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 6 Sep 2020 20:00:02 UTC Severity: important Tags: security, upstream Fo ...

Github Repositories

WP REST API enhancement to return JSON arrays containing localized strings registered with WordPress' wp_localize_script() function

RESTful Localized Scripts Contributors: shooper Donate link: shawnhooperca/ Tags: javascript, i18n, api Requires at least: 44 Tested up to: 442 Stable tag: trunk License: GPLv2 or later License URI: wwwgnuorg/licenses/gpl-20html WP REST API enhancement to return JSON arrays containing localized strings registered with WordPress' wp_localize_script()

Adds links to posts in other languages into the results of a WP REST API query for sites running the WPML plugin.

WPML REST API Contributors: shooper Donate link: shawnhooperca/ Tags: wpml, api, rest Requires at least: 52 Tested up to: 642 Requires PHP: 74 Stable tag: trunk License: GPLv2 or later License URI: wwwgnuorg/licenses/gpl-20html Get translations details with the WP REST API on sites running WordPress & WPML Description This plugin adds links to pag

Grunt module for Swagger specification validation

Grunt module for Swagger specification validation Updated to version v015 v015 2023/09/05 09:30 EDT - Fix CVE-2022-25883 vulnerabilities Updated to version v014 v014 2021/07/20 15:34 EDT - Fix CVE-2020-7729 vulnerabilities Updated to version v013 v010 This is an initial public release v011 Fix error v012 Fix error in jshint@255 v013 Updated the link as

cdcavellname Personal Website for Christopher D Cavell Project incorporates generation of markdown files in Documentation folder, during project builds, from comment syntax of source code, through console application XmlToMarkdown Documentation changes are maintained in a wiki submodule that is also updated during project build Target Frameworks are ASPNET Core 5