Fiche vulnérabilité
CVE-2021-36667 : faille élevée druva insync client (CVSS 7.8)
Description
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 12 juil. 2022
- Dernière mise à jour
- 9 juil. 2026
Produits concernés
- druva insync client