CVE-2021-36667

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:druva:insync_client:*:*:*:*:*:macos:*:*

Information

Published : 2022-07-12 07:15

Updated : 2022-07-20 09:22


NVD link : CVE-2021-36667

Mitre link : CVE-2021-36667


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

druva

  • insync_client