QID 375977

Date Published: 2021-10-28

QID 375977: Sourcetree for macOS and Windows Git Credential Disclosure Vulnerability

The embedded version of Git used in Sourcetree for macOS and Sourcetree for Windows is vulnerable. A Malicious URLs may cause Git to present stored credentials to the wrong server.

Affected Versions:
Sourcetree for Windows versions 3.3.8 and earlier
Sourcetree for macOS versions 4.0.1 and earlier

QID Detection Logic (Windows):
This authenticated QID detects vulnerable versions of SourceTree.exe by retrieving the path from the following registry entries:
HKLM\SOFTWARE\Atlassian\SourceTree for versions 1.x
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SourceTree for versions 2.x

QID Detection Logic (MacOS):
This authenticated QID detects vulnerable SourceTree installations by fetching the information from /Applications/SourceTree.app/Contents/Info.plist.

The attacker can trick the git utility into sending private credentials to a host controlled by an him and can retrieve passwords or other credentials from secure storage provided by the operating system

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to Sourcetree Security Advisory 2020-09-02 for more information pertaining to these vulnerabilities.

    CVEs related to QID 375977

    Software Advisories
    Advisory ID Software Component Link
    Sourcetree Security Advisory 2020-09-02 URL Logo confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2020-09-02-1021222895.html