Unrated severityNVD Advisory· Published Mar 8, 2019· Updated Sep 16, 2024
CVE-2018-20235
CVE-2018-20235
Description
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
Affected products
1- Range: 0.5a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.htmlmitrex_refsource_MISC
- www.securityfocus.com/bid/107407mitrevdb-entryx_refsource_BID
- jira.atlassian.com/browse/SRCTREEWIN-11289mitrex_refsource_CONFIRM
- seclists.org/bugtraq/2019/Mar/30mitremailing-listx_refsource_BUGTRAQ
News mentions
0No linked articles in our index yet.