Argument and Command Injection Vulnerability in Sourcetree for Windows by Atlassian
CVE-2017-14593
8.8HIGH
What is CVE-2017-14593?
Sourcetree for Windows contains vulnerabilities that involve argument and command injection through its handling of Mercurial and Git repositories. An attacker possessing the necessary permissions to commit to a linked repository can exploit these vulnerabilities, enabling them to execute arbitrary code on an affected system. This issue can be triggered through the Sourcetree URI handler, particularly from a webpage, affecting users from version 0.5.1.0 up to but not including 2.4.7.0. It is crucial for users to ensure that they are running secure versions of the software to mitigate potential attacks.
Affected Version(s)
Sourcetree for Windows Versions starting with 0.5.1.0 before version 2.4.7.0