Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://asana.com | product |
https://forum.asana.com/t/asana-desktop-app-security-update/160477 | release notes vendor advisory |