9.8

CVE-2023-46322

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iterm2Iterm2 Version <= 3.4.21
Iterm2Iterm2 Version3.5.0 Updatebeta1
Iterm2Iterm2 Version3.5.0 Updatebeta10
Iterm2Iterm2 Version3.5.0 Updatebeta2
Iterm2Iterm2 Version3.5.0 Updatebeta3
Iterm2Iterm2 Version3.5.0 Updatebeta4
Iterm2Iterm2 Version3.5.0 Updatebeta5
Iterm2Iterm2 Version3.5.0 Updatebeta6
Iterm2Iterm2 Version3.5.0 Updatebeta7
Iterm2Iterm2 Version3.5.0 Updatebeta8
Iterm2Iterm2 Version3.5.0 Updatebeta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-117 Improper Output Neutralization for Logs

The product does not neutralize or incorrectly neutralizes output that is written to logs.

https://iterm2.com/downloads.html
Vendor Advisory
https://gitlab.com/gnachman/iterm2/-/commit/ef7bb84520013b2524df9787d4aa9f2c96746c01
Third Party Advisory