Lucene search

K
cveMitreCVE-2023-49314
HistoryNov 28, 2023 - 3:15 p.m.

CVE-2023-49314

2023-11-2815:15:07
CWE-94
mitre
web.nvd.nist.gov
30
asana
desktop
macos
code injection
cve-2023-49314
electron fuses
security vulnerability
attack prevention

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

Affected configurations

Nvd
Node
asanadesktopMatch2.1.0
AND
applemacosMatch-
VendorProductVersionCPE
asanadesktop2.1.0cpe:2.3:a:asana:desktop:2.1.0:*:*:*:*:*:*:*
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2023-49314