VDB
Sign up
HIGH7.0

GHSA-rm36-94g8-835r

Race Condition in Grunt

Quick fix

GHSA-rm36-94g8-835r — grunt: upgrade to the fixed version with the command below.

npm install grunt@1.5.3

Details

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/grunt
Introduced in: 0Fixed in: 1.5.3
Fixnpm install grunt@1.5.3

References