9

CVE-2018-13396

There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtlassianSourcetree SwPlatformmac_os_x Version >= 1.0 < 3.0.0
AtlassianSourcetree Version1.0 Updatebeta2 SwPlatformmacos
AtlassianSourcetree Version1.0 Updatebeta3 SwPlatformmacos
AtlassianSourcetree Version1.0 Updatebeta4 SwPlatformmacos
AtlassianSourcetree Version1.0 Updatebeta5 SwPlatformmacos
AtlassianSourcetree Version1.0 Updaterc1 SwPlatformmacos
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://jira.atlassian.com/browse/SRCTREE-5985
Vendor Advisory
Issue Tracking