Vulnerabilities > Druva > Insync > 6.5.0

DATE CVE VULNERABILITY TITLE RISK
2020-03-24 CVE-2019-4001 Incorrect Default Permissions vulnerability in Druva Insync 6.5.0
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
local
low complexity
druva CWE-276
4.6
2020-02-25 CVE-2019-4000 Code Injection vulnerability in Druva Insync 6.5.0
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
local
low complexity
druva CWE-94
7.2