PT-2020-10930 · Druva+1 · Druva Insync Client+1
Published
2020-03-24
·
Updated
2021-07-21
·
CVE-2019-4001
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Druva inSync Client version 6.5.0
Description
The issue is related to improper input validation, allowing a local, authenticated attacker to execute arbitrary NodeJS code.
Recommendations
For Druva inSync Client version 6.5.0, update to a version that fixes the improper input validation issue to prevent arbitrary NodeJS code execution.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Druva Insync Client
Node.Js