First published: Tue Nov 28 2023(Updated: )
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Asana | =2.1.0 | |
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-49314.
The severity of CVE-2023-49314 is critical.
Asana Desktop version 2.1.0 on macOS is affected by CVE-2023-49314.
Code injection can be performed through specific Electron Fuses and inadequate protection against code injection settings such as RunAsNode and EnableNodeCliInspectArguments.
At the moment, there is no specific fix available for CVE-2023-49314. It is recommended to update to the latest version of Asana Desktop when a fix becomes available.