-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 3.4.2
-
Component/s: Git
-
9.1
-
Severity 1 - Critical
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. This is the result of an incomplete fix for CVE-2020-27955
Affected versions:
- Version 3.4.2 and earlier
Fix
- You can download the latest version of the standard installer or the enterprise installer.
For additional details, see the full advisory