-
Bug
-
Resolution: Fixed
-
Highest
-
1.4.0
-
None
-
Severity 1 - Critical
SourceTree for Mac is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
Affected versions:
- Versions of SourceTree for Mac starting with 1.4.0 before version 2.5.1 are affected by this vulnerability.
Fix:
- Upgrade SourceTree for Mac to version 2.5.1 or higher from https://www.sourcetreeapp.com/
Acknowledgements
We would like to credit Yu Hong for reporting this issue to us.
For additional details see the full advisory.
[SRCTREE-4738] Command Injection (CVE-2017-8768)
Link |
Original:
This issue relates to |
Workflow | Original: JAC Bug Workflow v3 [ 3369774 ] | New: SRCTREE JAC Bug Workflow [ 3737013 ] |
Workflow | Original: SourceTree Bug Workflow [ 2015638 ] | New: JAC Bug Workflow v3 [ 3369774 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Labels | Original: CVE-2017-8768 advisory cvss-high security | New: CVE-2017-8768 advisory command-injection cvss-high injection security |
Labels | Original: CVE-2017-8768 advisory cvss-high no-advisory-required security | New: CVE-2017-8768 advisory cvss-high security |
Attachment | New: Screen Shot 2017-05-11 at 6.21.24 PM.png [ 281016 ] |
Remote Link | Original: This issue links to "Page (Extranet)" [ 287054 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Description |
Original:
SourceTree for Mac is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
*Affected versions:* * Versions of SourceTree for Mac starting with 1.4.0 before version 2.5.1 are affected by this vulnerability. *Fix:* * Upgrade SourceTree for Mac to version 2.5.1 or higher from https://www.sourcetreeapp.com/ *Acknowledgements* We would like to credit redrain for reporting this issue to us. For additional details see [the full advisory|https://confluence.atlassian.com/x/jW2xNQ]. |
New:
SourceTree for Mac is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
*Affected versions:* * Versions of SourceTree for Mac starting with 1.4.0 before version 2.5.1 are affected by this vulnerability. *Fix:* * Upgrade SourceTree for Mac to version 2.5.1 or higher from https://www.sourcetreeapp.com/ *Acknowledgements* We would like to credit Yu Hong for reporting this issue to us. For additional details see [the full advisory|https://confluence.atlassian.com/x/jW2xNQ]. |
Description |
Original:
SourceTree for Mac is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
*Affected versions:* * Versions of SourceTree for Windows starting with 1.4.0 before version 2.5.1 are affected by this vulnerability. *Fix:* * Upgrade SourceTree for Mac to version 2.5.1 or higher from https://www.sourcetreeapp.com/ *Acknowledgements* We would like to credit redrain for reporting this issue to us. For additional details see [the full advisory|https://confluence.atlassian.com/x/jW2xNQ]. |
New:
SourceTree for Mac is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
*Affected versions:* * Versions of SourceTree for Mac starting with 1.4.0 before version 2.5.1 are affected by this vulnerability. *Fix:* * Upgrade SourceTree for Mac to version 2.5.1 or higher from https://www.sourcetreeapp.com/ *Acknowledgements* We would like to credit redrain for reporting this issue to us. For additional details see [the full advisory|https://confluence.atlassian.com/x/jW2xNQ]. |