Skip to main content

Vendor archive

druva CVEs

Beta · best-effort

9 CVEs tagged to vendor druva0 Critical, 9 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-36668

Published Jul 12, 2022

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36667

Published Jul 12, 2022

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized ca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36666

Published Jul 12, 2022

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36665

Published Jul 12, 2022

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5798

Published Dec 7, 2020

inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5752

Published May 21, 2020

Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4001

Published Mar 24, 2020

Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4000

Published Feb 25, 2020

Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3999

Published Feb 25, 2020

Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating syst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1