Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-38395
HistoryJun 16, 2024 - 12:00 a.m.

CVE-2024-38395

2024-06-1600:00:00
mitre
github.com
7
iterm2
v3.5.2
security issue
terminal
window title
setting
not honored
remote code execution

AI Score

8.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

In iTerm2 before 3.5.2, the “Terminal may report window title” setting is not honored, and thus remote code execution might occur but “is not trivially exploitable.”

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:*"
    ],
    "vendor": "iterm2",
    "product": "iterm2",
    "versions": [
      {
        "status": "affected",
        "version": "3.5.2"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

8.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-38395