CVE-2023-46301: Critical severity iterm2 vulnerability
Published Oct 22, 2023
·Updated
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
Affected Software
1 affected component
iTerm2 iTerm2<3.4.20
Remediation
Event History
Oct 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this iTerm2 vulnerability?
The vulnerability ID for this iTerm2 vulnerability is CVE-2023-46301.
2
What is the severity of CVE-2023-46301?
The severity of CVE-2023-46301 is critical with a severity value of 9.8.
3
How does iTerm2 before 3.4.20 allow code execution?
iTerm2 before 3.4.20 allows (potentially remote) code execution due to mishandling of certain escape sequences related to upload.
4
How can I fix the CVE-2023-46301 vulnerability?
To fix the CVE-2023-46301 vulnerability, update iTerm2 to version 3.4.20 or newer.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-46301?
The Common Weakness Enumeration (CWE) for CVE-2023-46301 is CWE-116.