Lucene search

K
cveGitHub_MCVE-2021-32692
HistoryDec 23, 2022 - 3:15 a.m.

CVE-2021-32692

2022-12-2303:15:07
CWE-78
CWE-77
GitHub_M
web.nvd.nist.gov
31
activity watch
cve-2021-32692
macos
arbitrary command execution
vulnerability
patch
aw-watcher-window
nvd

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.3%

Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visiting a website with the page title set to a malicious string. An attacker could use another application to accomplish the same, but the web browser is the most likely attack vector. This issue is patched in version 0.11.0. As a workaround, users can run the latest version of aw-watcher-window from source, or manually patch the printAppTitle.scpt file.

Affected configurations

Nvd
Vulners
Node
applemacosMatch-
AND
activitywatchactivitywatchRange<0.11.0
VendorProductVersionCPE
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
activitywatchactivitywatch*cpe:2.3:a:activitywatch:activitywatch:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "ActivityWatch",
    "product": "Activity Watch",
    "versions": [
      {
        "version": "0.11.0",
        "status": "affected",
        "lessThan": "0.11.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.3%

Related for CVE-2021-32692