CVE-2023-46322
23.10.2023, 00:15
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.Enginsight
Vendor | Product | Version |
---|---|---|
iterm2 | iterm2 | 𝑥 ≤ 3.4.21 |
iterm2 | iterm2 | 3.5.0:beta1 |
iterm2 | iterm2 | 3.5.0:beta10 |
iterm2 | iterm2 | 3.5.0:beta2 |
iterm2 | iterm2 | 3.5.0:beta3 |
iterm2 | iterm2 | 3.5.0:beta4 |
iterm2 | iterm2 | 3.5.0:beta5 |
iterm2 | iterm2 | 3.5.0:beta6 |
iterm2 | iterm2 | 3.5.0:beta7 |
iterm2 | iterm2 | 3.5.0:beta8 |
iterm2 | iterm2 | 3.5.0:beta9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration