9.8

CVE-2023-46321

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iterm2Iterm2 Version <= 3.4.21
Iterm2Iterm2 Version3.5.0 Updatebeta1
Iterm2Iterm2 Version3.5.0 Updatebeta10
Iterm2Iterm2 Version3.5.0 Updatebeta2
Iterm2Iterm2 Version3.5.0 Updatebeta3
Iterm2Iterm2 Version3.5.0 Updatebeta4
Iterm2Iterm2 Version3.5.0 Updatebeta5
Iterm2Iterm2 Version3.5.0 Updatebeta6
Iterm2Iterm2 Version3.5.0 Updatebeta7
Iterm2Iterm2 Version3.5.0 Updatebeta8
Iterm2Iterm2 Version3.5.0 Updatebeta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-117 Improper Output Neutralization for Logs

The product does not neutralize or incorrectly neutralizes output that is written to logs.

https://iterm2.com/downloads.html
Vendor Advisory
https://gitlab.com/gnachman/iterm2/-/commit/de3d351e1bd3bc1c1a4f85fe976c592e497dd071
Third Party Advisory