CVE-2018-13396
Sourcetree Git Arbitrary Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
Hay una vulnerabilidad de inyección de argumentos en Sourcetree para macOS desde la versión 1.0b2 hasta la 3.0.0 mediante los subrepositorios de Git en los repositorios de Mercurial. Un atacante con permisos para realizar commits en un repositorio Mercurial vinculado a Sourcetree para macOS puede explotar este problema para ejecutar código en el sistema.
An attacker can exploit the embedded version of Git used in Sourcetree if they can commit to a Git repository linked in Sourcetree. This allows them to execute arbitrary code on systems running a vulnerable version of Sourcetree for macOS. Versions of Sourcetree for macOS starting with version 1.02b before version 3.0.0 are affected by this vulnerability. Versions of Sourcetree for Windows starting with version 0.5.1.0 before version 3.0.0 are affected by this vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-06 CVE Reserved
- 2018-11-01 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.atlassian.com/browse/SRCTREE-5985 | 2020-05-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | >= 1.0 < 3.0.0 Search vendor "Atlassian" for product "Sourcetree" and version " >= 1.0 < 3.0.0" | mac_os_x |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | 1.0 Search vendor "Atlassian" for product "Sourcetree" and version "1.0" | beta2, macos |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | 1.0 Search vendor "Atlassian" for product "Sourcetree" and version "1.0" | beta3, macos |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | 1.0 Search vendor "Atlassian" for product "Sourcetree" and version "1.0" | beta4, macos |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | 1.0 Search vendor "Atlassian" for product "Sourcetree" and version "1.0" | beta5, macos |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Sourcetree Search vendor "Atlassian" for product "Sourcetree" | 1.0 Search vendor "Atlassian" for product "Sourcetree" and version "1.0" | rc1, macos |
Affected
|