First published: Sat Apr 09 2022(Updated: )
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asana | <1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26877 is a vulnerability in Asana Desktop before version 1.6.0 that allows remote attackers to exfiltrate local files if they can trick the app into loading a malicious web page.
CVE-2022-26877 allows remote attackers to steal local files by exploiting the vulnerability in Asana Desktop.
The severity of CVE-2022-26877 is medium, with a CVSS score of 6.5.
To protect yourself from CVE-2022-26877, make sure to update your Asana Desktop app to version 1.6.0 or newer.
You can find more information about CVE-2022-26877 on the Asana website and the official Asana forum.