asana CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

asana vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to asana, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-49314 Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack. [email protected] 7.8 17.64% 2023-11-28 2024-11-21
CVE-2022-26877 Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page. [email protected] 6.5 0.35% 2022-04-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence