CVE-2017-14593

CWE-77Command Injection3 documents3 sources
Severity
8.8HIGH
EPSS
2.1%
top 15.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateMay 13

Description

Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. From version 0.8.4b of Sourcetree for Windows, this vulnerability can be triggered from a webpage through the use of the Sourcetree URI handler. Versions of Sourcetree for Windows starting with 0.5.1.0 before version 2.4.7.0 are aff

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5atlassian/sourcetree_for_windowsVersions starting with 0.5.1.0 before version 2.4.7.0
NVDatlassian/sourcetree0.5.1.02.4.7.0

🔴Vulnerability Details

2
GHSA
GHSA-2h25-2cpj-6h2c: Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling2022-05-13
CVEList
CVE-2017-14593: Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling2018-01-26
CVE-2017-14593 (HIGH CVSS 8.8) | Sourcetree for Windows had several | cvebase.io