Uploaded image for project: 'Sourcetree for Windows'
  1. Sourcetree for Windows
  2. SRCTREEWIN-11289

Argument Injection via Mercurial hooks in Sourcetree for Windows - CVE-2018-20235

    • Severity 1 - Critical

      There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.

      Affected versions:

      • Versions of Sourcetree for Windows before version 3.0.15 are affected by this vulnerability

      Fix:

      For additional details, see the full advisory: https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2019-03-06-966678691.html

            [SRCTREEWIN-11289] Argument Injection via Mercurial hooks in Sourcetree for Windows - CVE-2018-20235

            Eric Franklin (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 847671 ]
            Eric Franklin (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 846040 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: JAC Bug Workflow v3 [ 3455444 ] New: SRCTREE JAC Bug Workflow [ 3745141 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: SourceTree Bug Workflow [ 3089750 ] New: JAC Bug Workflow v3 [ 3455444 ]
            David Black made changes -
            Labels Original: CVE-2018-20235 advisory advisory-to-release argument-injection bugbounty cvss-critical security New: CVE-2018-20235 advisory advisory-released argument-injection bugbounty cvss-critical security
            Erin Jensby made changes -
            Security Original: Atlassian Staff [ 10750 ]
            Security Metrics Bot made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Reopened [ 4 ] New: Closed [ 6 ]
            Security Metrics Bot made changes -
            Resolution Original: Fixed [ 1 ]
            Status Original: Closed [ 6 ] New: Reopened [ 4 ]
            Security Metrics Bot made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Reopened [ 4 ] New: Closed [ 6 ]
            Security Metrics Bot made changes -
            Resolution Original: Fixed [ 1 ]
            Status Original: Closed [ 6 ] New: Reopened [ 4 ]

              Unassigned Unassigned
              ejensby Erin Jensby
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: