CVE-2022-46387

Source
https://cve.org/CVERecord?id=CVE-2022-46387
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-46387.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-46387
Published
2023-03-28T00:00:00Z
Modified
2026-07-15T01:49:11.931904751Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "220807"
                },
                {
                    "fixed": "1.3.21"
                }
            ]
        }
    ],
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/46xxx/CVE-2022-46387.json"
}
References

Affected packages

Git / github.com/cmderdev/cmder

Affected ranges

Type
GIT
Repo
https://github.com/cmderdev/cmder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:cmder:cmder:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.2"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.0-beta
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.4.1
v1.2
v1.3.0
v1.3.0-pre
v1.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-46387.json"