Skip to content

iTerm2 app false negative vulnerability #25130

@rebeccaui

Description

@rebeccaui

Fleet version: 4.59.0

Web browser and operating system: macOS 15.2


💥  Actual behavior

Vulnerabilities are listed for the homebrew version of iterm2, but no vulnerabilities are listed for the iTerm 2.app version from the website.
It could be that the CPE Fleet generates for the .app version of iTerm does not match the CPE provided by VulnCheck.
CVE-2024-38395 is one of the vulnerabilities that should be showing up.

image

Left side is iTerm 2.app (App) with no vulnerabilities reported.
Right side is iterm2 (homebrew) with vulnerabilities reported.
image

image

image

🧑‍💻  Steps to reproduce

  1. Download/install iTerm2 from its website (iterm2.com).
  2. Note that no vulnerabilites appear.

🕯️ More info (optional)

N/A

Metadata

Metadata

Assignees

Labels

#g-softwareSoftware product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.bugSomething isn't working as documentedcustomer-stazzema~backendBackend-related issue.~released bugThis bug was found in a stable release.~vulnerability-management

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions