CVE-2023-46321

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
iterm2iterm2
𝑥
≤ 3.4.21
iterm2iterm2
3.5.0:beta1
iterm2iterm2
3.5.0:beta10
iterm2iterm2
3.5.0:beta2
iterm2iterm2
3.5.0:beta3
iterm2iterm2
3.5.0:beta4
iterm2iterm2
3.5.0:beta5
iterm2iterm2
3.5.0:beta6
iterm2iterm2
3.5.0:beta7
iterm2iterm2
3.5.0:beta8
iterm2iterm2
3.5.0:beta9
𝑥
= Vulnerable software versions