9.8

CVE-2023-46322

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iterm2 ≫ Iterm2 Version <= 3.4.21
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta1
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta10
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta2
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta3
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta4
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta5
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta6
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta7
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta8
Iterm2 ≫ Iterm2 Version 3.5.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-117 Improper Output Neutralization for Logs

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

https://iterm2.com/downloads.html
Vendor Advisory
https://gitlab.com/gnachman/iterm2/-/commit/ef7bb84520013b2524df9787d4aa9f2c96746c01
Third Party Advisory