inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
References
Link | Resource |
---|---|
https://www.tenable.com/security/research/tra-2020-67,https://docs.druva.com/001_inSync_Cloud/Cloud/010_Release_Details/010_inSync_Cloud_Updates | Third Party Advisory |
https://www.tenable.com/security/research/tra-2020-67 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-12-07 05:15
Updated : 2020-12-08 07:51
NVD link : CVE-2020-5798
Mitre link : CVE-2020-5798
JSON object : View
Products Affected
druva
- insync