{"dataType":"CVE_RECORD","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2025-22275","assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","dateUpdated":"2025-01-03T14:58:54.733Z","dateReserved":"2025-01-03T00:00:00.000Z","datePublished":"2025-01-03T00:00:00.000Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"iTerm2","vendor":"iTerm2","versions":[{"lessThan":"3.5.11","status":"affected","version":"3.5.6","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-532","description":"CWE-532 Insertion of Sensitive Information into Log File","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre","dateUpdated":"2025-01-03T06:23:55.308Z"},"references":[{"url":"https://iterm2.com/downloads/stable/iTerm2-3_5_11.changelog"},{"url":"https://news.ycombinator.com/item?id=42579472"},{"url":"https://gitlab.com/gnachman/iterm2/-/wikis/SSH-Integration-Information-Leak"}],"x_generator":{"engine":"enrichogram 0.0.1"},"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.6","versionEndExcluding":"3.5.11"}]}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-01-03T14:58:43.443113Z","id":"CVE-2025-22275","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-03T14:58:54.733Z"}}]},"dataVersion":"5.1"}