RCE via git-lfs in Sourcetree for Windows - CVE-2021-21237

XMLWordPrintable

    • 9.1
    • Severity 1 - Critical

      There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. This is the result of an incomplete fix for CVE-2020-27955

      Affected versions:

      • Version 3.4.2 and earlier

       

      Fix

       

      For additional details, see the full advisory

            Assignee:
            Unassigned
            Reporter:
            Mitchell Johnson (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: