Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
BID:107511
CVE-2018-17456 |Info
Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 107511 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-17456 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2019 12:00AM |
| Updated: | Mar 06 2019 12:00AM |
| Credit: | Terry Zhang (pnig0s) at Tophant |
| Vulnerable: |
Atlassian SourceTree 3.0.15 Atlassian SourceTree 3.0.12 Atlassian SourceTree 3.0.10 Atlassian SourceTree 3.0.8 Atlassian SourceTree 2.5.1 Atlassian SourceTree 2.5 Atlassian SourceTree 1.5 Atlassian SourceTree 1.4 Atlassian SourceTree 1.1 Atlassian SourceTree 3.1 Atlassian SourceTree 2.6.10.0 Atlassian SourceTree 2.5C Atlassian SourceTree 2.0.20.1 Atlassian SourceTree 2.0.20.0 Atlassian SourceTree 1.9.13.7 Atlassian SourceTree 1.7.0.32509 Atlassian SourceTree 1.6 Atlassian SourceTree 1.3 Atlassian SourceTree 1.0 Atlassian SourceTree 0.8.4b Atlassian SourceTree 0.5a |
| Not Vulnerable: |
Atlassian SourceTree 3.1.1 Atlassian SourceTree 3.0.17 |
Discussion
RETIRED: Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
Atlassian SourceTree is prone to an arbitrary code-execution vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary code, access or modify data within the context of the affected application; this may aid in further attacks.
Sourcetree for macOS prior to version 3.1.1 and Sourcetree for Windows prior to version 3.0.17 are vulnerable.
Retired as a duplicate of BID 105523 Git CVE-2018-17456 Arbitrary Code Execution Vulnerability.
Atlassian SourceTree is prone to an arbitrary code-execution vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary code, access or modify data within the context of the affected application; this may aid in further attacks.
Sourcetree for macOS prior to version 3.1.1 and Sourcetree for Windows prior to version 3.0.17 are vulnerable.
Retired as a duplicate of BID 105523 Git CVE-2018-17456 Arbitrary Code Execution Vulnerability.
Exploit / POC
RETIRED: Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RETIRED: Atlassian SourceTree CVE-2018-17456 Arbitrary Code Execution Vulnerability
References:
References:
- Atlassian Homepage (Atlassian)
- SourceTree Homepage (Atlassian)
- March 2019 Sourcetree Advisory - Multiple Remote Code Execution Vulnerabilities ()