QID 375592
Date Published: 2021-06-01
QID 375592: Atlassian Sourcetree for Windows Remote Code Execution Vulnerability
Sourcetree is a free Git client for Windows and Mac that simplifies how you interact with your repositories.
CVE-2019-11582 - An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
Affected Versions:
Sourcetree for Windows version 0.5a prior to 3.1.3
QID Detection Logic:
This QID checks for vulnerable version of Atlassian Sourcetree.
An attacker could gain remote code execution on the target system by exploiting this issue.
Solution
Customers are advised to download Sourcetree for Windows version 3.1.3 or higher to fix this vulnerability.
For more information refer to SRCTREEWIN-11917.
For more information refer to SRCTREEWIN-11917.
Vendor References
- SRCTREEWIN-11917 -
jira.atlassian.com/browse/SRCTREEWIN-11917
CVEs related to QID 375592
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SRCTREEWIN-11917 |
|