Atlassian Sourcetree For Windows vulnerabilities

8 known vulnerabilities affecting atlassian/sourcetree_for_windows.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8

Vulnerabilities

Page 1 of 1
CVE-2024-21697HIGHCVSS 8.8vAll versions from 3.4.19 to 3.4.192024-11-19
CVE-2024-21697 [HIGH] CVE-2024-21697: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sou This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, hi
cvelistv5nvd
CVE-2023-22514HIGHCVSS 7.8v>= 3.4.142024-01-16
CVE-2023-22514 [HIGH] CWE-94 CVE-2023-22514: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sou This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code w
cvelistv5nvd
CVE-2019-11582HIGHCVSS 8.8≥ 0.5a, < unspecified≥ unspecified, < 3.1.32019-06-14
CVE-2019-11582 [HIGH] CWE-88 CVE-2019-11582: An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versi An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
cvelistv5nvd
CVE-2018-20236HIGHCVSS 8.8≥ 0.5a, < unspecified≥ unspecified, < 3.0.102019-03-08
CVE-2018-20236 [HIGH] CWE-77 CVE-2018-20236: There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before vers There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.
cvelistv5nvd
CVE-2018-20235HIGHCVSS 8.8≥ 0.5a, < unspecified≥ unspecified, < 3.0.152019-03-08
CVE-2018-20235 [HIGH] CVE-2018-20235: There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
cvelistv5nvd
CVE-2018-13397HIGHCVSS 8.8≥ 0.5.1.0, < unspecified≥ unspecified, < 3.0.02018-11-05
CVE-2018-13397 [HIGH] CVE-2018-13397: There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
cvelistv5nvd
CVE-2018-13386HIGHCVSS 8.1≥ unspecified, < 2.6.92018-07-24
CVE-2018-13386 [HIGH] CWE-88 CVE-2018-13386: There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial r There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before version 2.6.9 are affected by this
cvelistv5nvd
CVE-2017-14593HIGHCVSS 8.8vVersions starting with 0.5.1.0 before version 2.4.7.02018-01-26
CVE-2017-14593 [HIGH] CWE-77 CVE-2017-14593: Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git reposito Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. From version 0.8.4b of Sourcetree for Windows, this vulnerability can be triggered fro
cvelistv5nvd