iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
In specific SSH Integration and it2ssh configurations, the iTerm2 application writes data from terminal sessions to the /tmp/framer.txt file on a remote host. This file can contain sensitive data — including commands executed in the terminal — and is potentially accessible to other users of the system or processes on that host. The vulnerability is exposed during remote SSH logins to hosts with a standard Python installation, which is required for the integration mechanism to function.
An attacker or other unauthorized user on a remote host can read the contents of the /tmp/framer.txt file and gain access to sensitive information from terminal sessions, such as executed commands that may potentially contain passwords, tokens, or other authentication data.
Update iTerm2 to version 3.5.11 or later, in which the issue has been fixed. Details of the fix are available in the vendor's changelog at the address provided in the references.
iTerm2 in versions 3.5.6 to 3.5.10 (prior to 3.5.11), with active it2ssh or SSH Integration configuration, during connections to hosts with Python installed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NIterm2
APPIterm23.5.6 – 3.5.11 (excl.)
Related vulnerabilities
iTerm2: RCE przez niezastosowanie ustawienia tytułu okna terminala
iTerm2: wstrzyknięcie kodu przez sekwencję escape w integracji tmux (RCE)
iTerm2: brak sanityzacji ścieżek w URL-ach x-man-page umożliwia wstrzyknięcie poleceń
iTerm2: brak sanityzacji nazwy hosta SSH w URL przed wersją 3.5.0beta12
RCE w iTerm2 przez nieprawidłową obsługę sekwencji escape w integracji tmux