CVE-2023-49314

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:asana:desktop:2.1.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-28 15:15

Updated : 2024-02-16 16:15


NVD link : CVE-2023-49314

Mitre link : CVE-2023-49314

CVE.ORG link : CVE-2023-49314


JSON object : View

Products Affected

asana

  • desktop

apple

  • macos
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')