Filtered by vendor Asana
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-49314 | 2 Apple, Asana | 2 Macos, Desktop | 2024-02-16 | N/A | 7.8 HIGH |
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack. | |||||
CVE-2022-26877 | 1 Asana | 1 Desktop | 2024-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page. |