CVE-2019-11582

CWE-883 documents3 sources
Severity
8.8HIGH
EPSS
1.9%
top 16.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateMay 24

Description

An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5atlassian/sourcetree_for_windows0.5aunspecified+1
NVDatlassian/sourcetree0.5a3.1.3

🔴Vulnerability Details

2
GHSA
GHSA-9rhm-rvmr-h9q2: An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 32022-05-24
CVEList
CVE-2019-11582: An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 32019-06-14