Command Injection Vulnerability in Sourcetree for Windows
CVE-2018-20236

8.8HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
8 March 2019

Summary

A command injection vulnerability exists in Sourcetree for Windows that permits remote attackers to send crafted URIs, leading to arbitrary code execution. Affected users running versions from 0.5a up to 3.0.9 are at risk, as the vulnerability arises from improper URI handling within the application. Malicious actors can exploit this flaw by delivering specially designed URIs to victims, which Sourcetree processes, potentially compromising the victim's system.

Affected Version(s)

Sourcetree for Windows 0.5a

Sourcetree for Windows < 3.0.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.