-
Bug
-
Resolution: Fixed
-
Low
-
3.4.2
-
9.1
-
Severity 1 - Critical
There was an argument injection vulnerability in SourceTree for Windows introduced through git-lfs. An attacker could create a malicious repository which, after being cloned in SourceTree for Windows and enabled with git-lfs, is able to exploit this issue to gain code execution on the system. This is the result of an incomplete fix for CVE-2020-27955
Affected versions:
- Version 3.4.2 and earlier
Fix
- You can download the latest version of the standard installer or the enterprise installer.
For additional details, see the full advisory