← Back

CVE-2023-49314

nvd nist
Published: Nov 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

Affected (1)

Products: Asana: Desktop
1 product
Desktop
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0
Running on/withPlatform Versions
Apple
Macos
All versions

References (12)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Product
Source: cve@mitre.org
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description

Timeline

No history available yet.