Uploaded image for project: 'Sourcetree For Mac'
  1. Sourcetree For Mac
  2. SRCTREE-4481

Shell Injection in SourceTree for Mac

    XMLWordPrintable

Details

    • Severity 2 - Major

    Description

      SourceTree for Mac had a shell injection vulnerability starting with 1.9.8 prior to 2.3.1 (the fixed version). By visiting a malicious website or by convincing a user to click a sourcetree:// URL with a vulnerable version of SourceTree for Mac installed an attacker could use a shell injection vulnerability to execute arbitrary commands on a victims machine.

       

      Affected versions:

      • All versions of SourceTree for Mac from 1.9.8 before 2.3.1 (the fixed version) are affected by this vulnerability. 

      Fix:

       

      Acknowledgements:

      We would like to credit Matthew Diaz of NCC Group Security Advisory for reporting this issue to us.

      Attachments

        Activity

          People

            Unassigned Unassigned
            dblack David Black
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: