CVE-2021-3769
Last modified
CVE-2021-3769 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be exploited. **Fixed in**: [b3ba9978](https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978). **Impacted areas**: - `pygmalion` theme. - `pygmalion-virtualenv` theme. - `refined` theme.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Planetargon | Oh My Zsh | < 2021-11-11 |
References
- https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978Patch, Third Party Advisory
- https://github.com/ohmyzsh/ohmyzsh/commit/b3ba9978Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3769?
How severe is CVE-2021-3769?
How do I fix CVE-2021-3769?
Are you affected by CVE-2021-3769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
