• Severity 2 - Major

      SourceTree downloads the standalone Git and every other zips over HTTP from the Atlassian servers. This is not secure and should be switched to HTTPS.

            [SRCTREEWIN-7579] Git downloads over HTTP

            CVSS v3 score: 3.5 => Low severity

            Exploitability Metrics

            Attack Vector Adjacent
            Attack Complexity Low
            Privileges Required None
            User Interaction Required

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

            See http://go.atlassian.com/cvss for more details.

            Ashley Blackmore added a comment - CVSS v3 score: 3.5 => Low severity Exploitability Metrics Attack Vector Adjacent Attack Complexity Low Privileges Required None User Interaction Required Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity None Availability None See http://go.atlassian.com/cvss for more details.

              mminns minnsey
              ae8c7bdc99dd Stanzilla
              Affected customers:
              1 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: