Description
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-8672 | iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories. |
References
| Link | Providers |
|---|---|
| https://gitlab.com/gnachman/iterm2/issues/8491 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:02:39.819Z
Reserved: 2019-11-17T00:00:00.000Z
Link: CVE-2019-19022
No data.
Status : Modified
Published: 2019-11-17T18:15:11.503
Modified: 2024-11-21T04:34:00.880
Link: CVE-2019-19022
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD