Uploaded image for project: 'Sourcetree For Mac'
  1. Sourcetree For Mac
  2. SRCTREE-6394

Input validation vulnerability via Git in Sourcetree for Mac - CVE-2018-17456

    • Severity 1 - Critical

      There was an input validation vulnerability in Sourcetree for macOS via a Git repository with submodules. A remote attacker with permission to commit to a Git repository linked in Sourcetree for macOS is able to able to exploit this issue to gain code execution on the system.

      Affected versions:

      • Versions of Sourcetree for macOS before version 3.1.1 are affected by this vulnerability

      Fix:

      For additional details, see the full advisory: https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2019-03-06-966678691.html

            [SRCTREE-6394] Input validation vulnerability via Git in Sourcetree for Mac - CVE-2018-17456

            Eric Franklin (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 847672 ]
            Eric Franklin (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 846159 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: JAC Bug Workflow v3 [ 3372947 ] New: SRCTREE JAC Bug Workflow [ 3738087 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: SourceTree Bug Workflow [ 3089798 ] New: JAC Bug Workflow v3 [ 3372947 ]
            David Black made changes -
            Link New: This issue is detailed by SRCTREE-6297 [ SRCTREE-6297 ]
            David Black made changes -
            Labels Original: CVE-2018-17456 advisory advisory-to-release bugbounty cvss-critical input-validation security New: CVE-2018-17456 advisory advisory-released bugbounty cvss-critical input-validation security
            Erin Jensby made changes -
            Security Original: Atlassian Staff [ 10750 ]
            Erin Jensby made changes -
            Description Original: There was an input validation vulnerability in Sourcetree for macOS via a Git repository with submodules. A remote attacker with permission to commit to a Git repository linked in Sourcetree for macOS is able to able to exploit this issue to gain code execution on the system.
            h4. Affected versions:
             * Versions of Sourcetree for macOS before version 3.1.1 are affected by this vulnerability

            h4. Fix:
             * Upgrade Sourcetree for macOS to version 3.1.1 or higher from [https://www.sourcetreeapp.com/]

            For additional details, see the full advisory <insert CAC page>.

             
            New: There was an input validation vulnerability in Sourcetree for macOS via a Git repository with submodules. A remote attacker with permission to commit to a Git repository linked in Sourcetree for macOS is able to able to exploit this issue to gain code execution on the system.
            h4. Affected versions:
             * Versions of Sourcetree for macOS before version 3.1.1 are affected by this vulnerability

            h4. Fix:
             * Upgrade Sourcetree for macOS to version 3.1.1 or higher from [https://www.sourcetreeapp.com/]

            For additional details, see the full advisory: https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2019-03-06-966678691.html
            Erin Jensby made changes -
            Fix Version/s New: 3.1.1 [ 85794 ]
            AB made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 410422 ]

              Unassigned Unassigned
              ejensby Erin Jensby
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: