CVE-2022-42797Injection in Apple Xcode

CWE-74Injection4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 48.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27

Description

An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5apple/xcodeunspecified14.1
NVDapple/xcode< 14.1

🔴Vulnerability Details

2
CVEList
CVE-2022-42797: An injection issue was addressed with improved input validation2023-02-27
GHSA
GHSA-vgvf-4jhr-3w37: An injection issue was addressed with improved input validation2023-02-27

📋Vendor Advisories

1
Apple
CVE-2022-42797: Xcode 14.12022-11-01
CVE-2022-42797 — Injection in Apple Xcode | cvebase