Vulnerabilities > Druva

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2021-36665 Deserialization of Untrusted Data vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
local
low complexity
druva CWE-502
7.2
2022-07-12 CVE-2021-36666 Untrusted Search Path vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
local
low complexity
druva CWE-426
7.8
2022-07-12 CVE-2021-36667 OS Command Injection vulnerability in Druva Insync Client
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
local
low complexity
druva CWE-78
4.6
2022-07-12 CVE-2021-36668 Injection vulnerability in Druva Insync Client
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
local
low complexity
druva CWE-74
4.6
2020-12-07 CVE-2020-5798 Improper Validation of Integrity Check Value vulnerability in Druva Insync 6.8.0
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
local
low complexity
druva CWE-354
7.8
2020-05-21 CVE-2020-5752 Path Traversal vulnerability in Druva Insync Client 6.6.3
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
local
low complexity
druva CWE-22
7.8
2020-03-24 CVE-2019-4001 Incorrect Default Permissions vulnerability in Druva Insync 6.5.0
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
local
low complexity
druva CWE-276
4.6
2020-02-25 CVE-2019-4000 Code Injection vulnerability in Druva Insync 6.5.0
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
local
low complexity
druva CWE-94
7.2
2020-02-25 CVE-2019-3999 OS Command Injection vulnerability in Druva Insync Client 6.5.0
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
local
low complexity
druva CWE-78
7.2