QID 375977
Date Published: 2021-10-28
QID 375977: Sourcetree for macOS and Windows Git Credential Disclosure Vulnerability
The embedded version of Git used in Sourcetree for macOS and Sourcetree for Windows is vulnerable. A Malicious URLs may cause Git to present stored credentials to the wrong server.
Affected Versions:
Sourcetree for Windows versions 3.3.8 and earlier
Sourcetree for macOS versions 4.0.1 and earlier
QID Detection Logic (Windows):
This authenticated QID detects vulnerable versions of SourceTree.exe by retrieving the path from the following registry entries:
HKLM\SOFTWARE\Atlassian\SourceTree for versions 1.x
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SourceTree for versions 2.x
QID Detection Logic (MacOS):
This authenticated QID detects vulnerable SourceTree installations by fetching the information from /Applications/SourceTree.app/Contents/Info.plist.
The attacker can trick the git utility into sending private credentials to a host controlled by an him and can retrieve passwords or other credentials from secure storage provided by the operating system
- Sourcetree Security Advisory 2020-09-02 -
confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2020-09-02-1021222895.html
CVEs related to QID 375977
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Sourcetree Security Advisory 2020-09-02 |
|