-
Bug
-
Resolution: Fixed
-
Low
-
None
-
3.3.9
-
Severity 1 - Critical
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.
Affected versions:
- Version 3.3.9 and earlier
Fix
- You can download the latest version of the standard installer or the enterprise installer.
For additional details, see the full advisory
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 9.1 => Critical severity
Exploitability Metrics
Scope Metric
Impact Metrics
See http://go.atlassian.com/cvss for more details.
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N