PT-2020-10930 · Druva+1 · Druva Insync Client+1

Published

2020-03-24

·

Updated

2021-07-21

·

CVE-2019-4001

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Druva inSync Client version 6.5.0
Description The issue is related to improper input validation, allowing a local, authenticated attacker to execute arbitrary NodeJS code.
Recommendations For Druva inSync Client version 6.5.0, update to a version that fixes the improper input validation issue to prevent arbitrary NodeJS code execution.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4001

Affected Products

Druva Insync Client
Node.Js