CVE-2023-46322: Critical severity iterm2 vulnerability
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46322?
CVE-2023-46322 is a vulnerability in iTerm2 before version 3.5.0beta12 that allows for the execution of arbitrary code.
How does CVE-2023-46322 affect iTerm2?
CVE-2023-46322 affects iTerm2 versions up to and including 3.4.21, as well as some beta versions of 3.5.0.
What is the severity of CVE-2023-46322?
CVE-2023-46322 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2023-46322?
To fix CVE-2023-46322, it is recommended to update to iTerm2 version 3.5.0beta12 or later.
Where can I find more information about CVE-2023-46322?
You can find more information about CVE-2023-46322 at the following references: [https://iterm2.com/downloads.html](https://iterm2.com/downloads.html) and [https://gitlab.com/gnachman/iterm2/-/commit/ef7bb84520013b2524df9787d4aa9f2c96746c01](https://gitlab.com/gnachman/iterm2/-/commit/ef7bb84520013b2524df9787d4aa9f2c96746c01).