CVE-2023-46322

EUVD-2023-50543
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
iterm2iterm2
𝑥
≤ 3.4.21
iterm2iterm2
3.5.0:beta1
iterm2iterm2
3.5.0:beta10
iterm2iterm2
3.5.0:beta2
iterm2iterm2
3.5.0:beta3
iterm2iterm2
3.5.0:beta4
iterm2iterm2
3.5.0:beta5
iterm2iterm2
3.5.0:beta6
iterm2iterm2
3.5.0:beta7
iterm2iterm2
3.5.0:beta8
iterm2iterm2
3.5.0:beta9
𝑥
= Vulnerable software versions