CVE-2019-19022

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/11/2019
Last modified:
19/11/2019

Description

iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* 3.3.6 (including)


References to Advisories, Solutions, and Tools