PT-2024-8649 · Atlassian · Sourcetree For Windows+1

Published

2024-11-19

·

Updated

2024-11-20

·

CVE-2024-21697

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sourcetree for Mac versions 4.2.8 Sourcetree for Windows versions 3.4.19
Description The issue is related to incorrect code generation management in the visual Git client SourceTree. Exploitation of this issue may allow a remote attacker to execute arbitrary code, which has a high impact on confidentiality, integrity, and availability, and requires user interaction.
Recommendations For Sourcetree for Mac version 4.2.8, upgrade to a release greater than or equal to 4.2.9. For Sourcetree for Windows version 3.4.19, upgrade to a release greater than or equal to 3.4.20.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10241
CVE-2024-21697

Affected Products

Sourcetree For Mac
Sourcetree For Windows