
CVE-2019-11582
https://notcve.org/view.php?id=CVE-2019-11582
14 Jun 2019 — An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI. Una vulnerabilidad de inyección argumental en los controladores de URI de Atlassian Sourcetree para Windows, en todas las versiones anteriores a 3.1.3, permite a los atacantes remotos conseguir la ejecución de código remota mediante el uso de un URI creado. • https://jira.atlassian.com/browse/SRCTREEWIN-11917 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVE-2018-20234 – Sourcetree Git Arbitrary Code Execution / URL Handling
https://notcve.org/view.php?id=CVE-2018-20234
08 Mar 2019 — There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Hay una vulnerabilidad de inyección de argumentos en Atlassian Sourcetree para macOS, desde la versión 1.2 hasta la versión 3.1.1, mediante nombres de archivos en repositorios Mercuria... • http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.html • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVE-2018-20235 – Sourcetree Git Arbitrary Code Execution / URL Handling
https://notcve.org/view.php?id=CVE-2018-20235
08 Mar 2019 — There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Hay una vulnerabilidad de inyección de argumentos en Atlassian Sourcetree para Windows, desde la versión 0.5a hasta la versión 3.0.15, mediante nombres de archivos en repositorio... • http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.html •

CVE-2018-20236 – Sourcetree Git Arbitrary Code Execution / URL Handling
https://notcve.org/view.php?id=CVE-2018-20236
08 Mar 2019 — There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system. Había una vulnerabilidad de inyección de comandos en Sourcetree para Windows, desde la versión 0.5a hasta la 3.0.10, mediante la gestión de URI. Un atacante remoto podría enviar una URL maliciosa a una víctima que utiliza Sourcetree para... • http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2018-13396 – Sourcetree Git Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2018-13396
01 Nov 2018 — There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Hay una vulnerabilidad de inyección de argumentos en Sourcetree para macOS desde la versión 1.0b2 hasta la 3.0.0 mediante los subrepositorios de Git en los repositorios de Mercurial. Un at... • https://jira.atlassian.com/browse/SRCTREE-5985 •

CVE-2018-13397 – Sourcetree Git Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2018-13397
01 Nov 2018 — There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Hay una vulnerabilidad de inyección de argumentos en Sourcetree para Windows desde la versión 0.5.1.0 hasta la 3.0.0 mediante los subrepositorios de Git en los repositorios de Mercur... • https://jira.atlassian.com/browse/SRCTREEWIN-9077 •

CVE-2018-13385 – Sourcetree Remote Code Execution
https://notcve.org/view.php?id=CVE-2018-13385
24 Jul 2018 — There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2 before 2.7.6 are affected by this vulnerability. Hubo una vulnerabilidad de inyección de argumentos en Sourcetree para macOS mediante nombres de archivos en repositorios Mercurial. Un atacante c... • https://jira.atlassian.com/browse/SRCTREE-5846 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVE-2018-13386 – Sourcetree Remote Code Execution
https://notcve.org/view.php?id=CVE-2018-13386
24 Jul 2018 — There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before version 2.6.9 are affected by this vulnerability. Hay una vulnerabilidad de inyección de argumentos en Sourcetree para Windows mediante nombres de archivo en repositorios Mercurial. Un atacant... • https://jira.atlassian.com/browse/SRCTREEWIN-8884 • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •

CVE-2018-5226 – SourceTree for Windows Argument Injection
https://notcve.org/view.php?id=CVE-2018-5226
25 Apr 2018 — There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions of Sourcetree for Windows before 2.5.5.0 are affected by this vulnerability. Había una vulnerabilidad de inyección de argumentos en Sourcetree para Windows mediante un nombre de etiqueta de rep... • https://jira.atlassian.com/browse/SRCTREEWIN-8509 •

CVE-2017-14592 – SourceTree Remote Command Injection
https://notcve.org/view.php?id=CVE-2017-14592
26 Jan 2018 — Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. From version 1.4.0 of Sourcetree for macOS, this vulnerability can be triggered from a webpage through the use of the Sourcetree URI handler. Versions of Sourcetree for macOS starting with 1.0b2 before version 2.7.0 are affected by this vulnerabili... • http://www.securityfocus.com/bid/102926 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •