Fedora Account System
Red Hat Associate
Red Hat Customer
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. Reference: https://snyk.io/vuln/SNYK-JS-GRUNT-597546 Upstream commit: https://github.com/gruntjs/grunt/commit/e350cea1724eb3476464561a380fb6a64e61e4e7
Created nodejs-grunt tracking bugs for this issue: Affects: epel-all [bug 1875432] Affects: fedora-all [bug 1875431]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.