Command Injection Vulnerability in Sourcetree for Windows
CVE-2018-20236
8.8HIGH
Summary
A command injection vulnerability exists in Sourcetree for Windows that permits remote attackers to send crafted URIs, leading to arbitrary code execution. Affected users running versions from 0.5a up to 3.0.9 are at risk, as the vulnerability arises from improper URI handling within the application. Malicious actors can exploit this flaw by delivering specially designed URIs to victims, which Sourcetree processes, potentially compromising the victim's system.
Affected Version(s)
Sourcetree for Windows 0.5a
Sourcetree for Windows < 3.0.10
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved