9.8

CVE-2023-46321

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iterm2Iterm2 Version <= 3.4.21
Iterm2Iterm2 Version3.5.0 Updatebeta1
Iterm2Iterm2 Version3.5.0 Updatebeta10
Iterm2Iterm2 Version3.5.0 Updatebeta2
Iterm2Iterm2 Version3.5.0 Updatebeta3
Iterm2Iterm2 Version3.5.0 Updatebeta4
Iterm2Iterm2 Version3.5.0 Updatebeta5
Iterm2Iterm2 Version3.5.0 Updatebeta6
Iterm2Iterm2 Version3.5.0 Updatebeta7
Iterm2Iterm2 Version3.5.0 Updatebeta8
Iterm2Iterm2 Version3.5.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.561
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-117 Improper Output Neutralization for Logs

The product does not neutralize or incorrectly neutralizes output that is written to logs.