CVE-2018-20235
08.03.2019, 18:29
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.Enginsight
Vendor | Product | Version |
---|---|---|
atlassian | sourcetree | 0.5a ≤ 𝑥 < 3.0.15 |
𝑥
= Vulnerable software versions
References