9.8
CVE-2018-13385
- EPSS 0.45%
- Veröffentlicht 24.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:00
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2 before 2.7.6 are affected by this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Sourcetree SwPlatformmac_os_x Version >= 1.0 < 2.7.6
Atlassian ≫ Sourcetree Version1.0 Updatebeta2 SwPlatformmacos
Atlassian ≫ Sourcetree Version1.0 Updatebeta3 SwPlatformmacos
Atlassian ≫ Sourcetree Version1.0 Updatebeta4 SwPlatformmacos
Atlassian ≫ Sourcetree Version1.0 Updatebeta5 SwPlatformmacos
Atlassian ≫ Sourcetree Version1.0 Updaterc1 SwPlatformmacos
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.629 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.