-
Notifications
You must be signed in to change notification settings - Fork 899
iTerm2 app false negative vulnerability #25130
Copy link
Copy link
Closed
Labels
#g-softwareSoftware product groupSoftware product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.bugSomething isn't working as documentedSomething isn't working as documentedcustomer-stazzema~backendBackend-related issue.Backend-related issue.~released bugThis bug was found in a stable release.This bug was found in a stable release.~vulnerability-management
Milestone
Metadata
Metadata
Assignees
Labels
#g-softwareSoftware product groupSoftware product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.bugSomething isn't working as documentedSomething isn't working as documentedcustomer-stazzema~backendBackend-related issue.Backend-related issue.~released bugThis bug was found in a stable release.This bug was found in a stable release.~vulnerability-management
Type
Fields
Give feedbackNo fields configured for issues without a type.
Fleet version: 4.59.0
Web browser and operating system: macOS 15.2
💥 Actual behavior
Vulnerabilities are listed for the homebrew version of iterm2, but no vulnerabilities are listed for the iTerm 2.app version from the website.
It could be that the CPE Fleet generates for the .app version of iTerm does not match the CPE provided by VulnCheck.
CVE-2024-38395 is one of the vulnerabilities that should be showing up.
Left side is iTerm 2.app (App) with no vulnerabilities reported.

Right side is iterm2 (homebrew) with vulnerabilities reported.
🧑💻 Steps to reproduce
🕯️ More info (optional)
N/A