CVE Vulnerabilities

CVE-2018-13396

Published: Nov 05, 2018 | Modified: May 11, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.

Affected Software

Name Vendor Start Version End Version
Sourcetree Atlassian 1.0 (including) 3.0.0 (excluding)
Sourcetree Atlassian 1.0-beta2 (including) 1.0-beta2 (including)
Sourcetree Atlassian 1.0-beta3 (including) 1.0-beta3 (including)
Sourcetree Atlassian 1.0-beta4 (including) 1.0-beta4 (including)
Sourcetree Atlassian 1.0-beta5 (including) 1.0-beta5 (including)
Sourcetree Atlassian 1.0-rc1 (including) 1.0-rc1 (including)

References