CVE-2022-23611

iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commit cdcd48b. Users are advised to upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:itunesrpc-remastered_project:itunesrpc-remastered:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
References () https://github.com/bildsben/iTunesRPC-Remastered/commit/cdcd48bbc44009ddcbd07a809b87376dc9ce37f4 - Patch, Third Party Advisory () https://github.com/bildsben/iTunesRPC-Remastered/commit/cdcd48bbc44009ddcbd07a809b87376dc9ce37f4 - Patch, Third Party Advisory
References () https://github.com/bildsben/iTunesRPC-Remastered/security/advisories/GHSA-mjv7-r62p-vhhg - Third Party Advisory () https://github.com/bildsben/iTunesRPC-Remastered/security/advisories/GHSA-mjv7-r62p-vhhg - Third Party Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 8.1

Information

Published : 2022-02-04 23:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23611

Mitre link : CVE-2022-23611

CVE.ORG link : CVE-2022-23611


JSON object : View

Products Affected

itunesrpc-remastered_project

  • itunesrpc-remastered
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')