Atlassian SourceTree Multiple Command Injection and Command Execution Vulnerabilities
BID:102926
CVE-2017-14592 | CVE-2017-14593 |Info
Atlassian SourceTree Multiple Command Injection and Command Execution Vulnerabilities
| Bugtraq ID: | 102926 |
| Class: | Unknown |
| CVE: |
CVE-2017-14592 CVE-2017-14593 CVE-2017-17458 CVE-2017-17831 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2018 12:00AM |
| Updated: | Jan 24 2018 12:00AM |
| Credit: | ZhangTianqi @ Tophant |
| Vulnerable: |
Atlassian SourceTree for Windows 2.1.10 Atlassian SourceTree for Windows 0.5.1.0 Atlassian SourceTree for macOS 2.6.1 Atlassian SourceTree for macOS 1.0b2 |
| Not Vulnerable: |
Atlassian SourceTree for Windows 2.4.7.0 Atlassian SourceTree for macOS 2.7.0 |
Discussion
Atlassian SourceTree Multiple Command Injection and Command Execution Vulnerabilities
Atlassian SourceTree is prone to a command-execution vulnerability and multiple remote command-injection vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts may cause a denial-of-service condition.
These issues are fixed in the following:
Sourcetree for macOS 2.7.0
Sourcetree for Windows 2.4.7.0
Atlassian SourceTree is prone to a command-execution vulnerability and multiple remote command-injection vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts may cause a denial-of-service condition.
These issues are fixed in the following:
Sourcetree for macOS 2.7.0
Sourcetree for Windows 2.4.7.0
Solution / Fix
Atlassian SourceTree Multiple Command Injection and Command Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Atlassian SourceTree Multiple Command Injection and Command Execution Vulnerabilities
References:
References:
- Atlassian Homepage (Atlassian)
- SourceTree Homepage (Atlassian)
- Sourcetree Security Advisory 2018-01-24 (Atlassian)