RCE via git-lfs in Sourcetree for Windows - CVE-2020-27955

XMLWordPrintable

    • Severity 1 - Critical

      There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.

      Affected versions:

      • Version 3.3.9 and earlier

       

      Fix

       

      For additional details, see the full advisory

            Assignee:
            Unassigned
            Reporter:
            Mitchell Johnson (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: