CVE-2018-20234
08.03.2019, 18:29
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
Vendor | Product | Version |
---|---|---|
atlassian | sourcetree | 1.2.0 ≤ 𝑥 < 3.1.1 |
𝑥
= Vulnerable software versions
References