CVE-2022-42797

An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.
References
Link Resource
https://support.apple.com/en-us/HT213496 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213496 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:25

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de inyección con una validación de entrada mejorada. Este problema se solucionó en Xcode 14.1. Es posible que una aplicación pueda obtener privilegios de superusuario.
References () https://support.apple.com/en-us/HT213496 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT213496 - Release Notes, Vendor Advisory

Information

Published : 2023-02-27 20:15

Updated : 2024-11-21 07:25


NVD link : CVE-2022-42797

Mitre link : CVE-2022-42797

CVE.ORG link : CVE-2022-42797


JSON object : View

Products Affected

apple

  • xcode
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')