-
Bug
-
Resolution: Fixed
-
Low
-
None
-
3.3.9
-
Severity 1 - Critical
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.
Affected versions:
- Version 3.3.9 and earlier
Fix
- You can download the latest version of the standard installer or the enterprise installer.
For additional details, see the full advisory
[SRCTREEWIN-13410] RCE via git-lfs in Sourcetree for Windows - CVE-2020-27955
Remote Link | New: This issue links to "Page (Confluence)" [ 847573 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 846036 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Description |
Original:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.
*Affected versions:* * Version 3.3.9 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+27th+January+2021] |
New:
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system.
*Affected versions:* * Version 3.3.9 and earlier *Fix* * You can download the latest version of the [standard installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourceTreeSetup-3.3.9.exe] or the [enterprise installer|https://product-downloads.atlassian.com/software/sourcetree/windows/ga/SourcetreeEnterpriseSetup_3.3.9.msi]. For additional details, see the [full advisory|https://confluence.atlassian.com/display/SOURCETREEKB/SourceTree+for+Windows+Security+Advisory+24th+March+2021] |
Link |
New:
This issue was cloned as |
Remote Link | New: This issue links to "Page (Confluence)" [ 525376 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 524070 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 524069 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Labels | New: advisory cvss-critical security |