Vulnerabilities > Druva > Insync Client
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-12 | CVE-2021-36665 | Deserialization of Untrusted Data vulnerability in Druva Insync Client An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon. | 7.2 |
2022-07-12 | CVE-2021-36666 | Untrusted Search Path vulnerability in Druva Insync Client An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission. | 7.8 |
2022-07-12 | CVE-2021-36667 | OS Command Injection vulnerability in Druva Insync Client Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library. | 4.6 |
2022-07-12 | CVE-2021-36668 | Injection vulnerability in Druva Insync Client URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App. | 4.6 |
2020-05-21 | CVE-2020-5752 | Path Traversal vulnerability in Druva Insync Client 6.6.3 Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. | 7.8 |
2020-02-25 | CVE-2019-3999 | OS Command Injection vulnerability in Druva Insync Client 6.5.0 Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. | 7.2 |