Vulnerabilities > Druva > Insync Client > 6.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2021-36665 Deserialization of Untrusted Data vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
local
low complexity
druva CWE-502
7.2
2022-07-12 CVE-2021-36668 Injection vulnerability in Druva Insync Client
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
local
low complexity
druva CWE-74
4.6