PT-2019-10029 · Atlassian · Sourcetree For Windows

Pnig0S

+1

·

Published

2019-03-08

·

Updated

2019-10-03

·

CVE-2018-20236

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sourcetree for Windows versions 0.5a through 3.0.9
Description: A command injection issue exists via URI handling, allowing a remote attacker to send a malicious URI to a victim using Sourcetree for Windows, potentially leading to code execution on the system.
Recommendations: For Sourcetree for Windows versions 0.5a through 3.0.9, update to version 3.0.10 or later to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20236

Affected Products

Sourcetree For Windows