Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvw9-7543-rjjg

Опубликовано: 23 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

EPSS

Процентиль: 56%
0.0034
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-117

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

EPSS

Процентиль: 56%
0.0034
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-117