CVE-2018-13386: High severity Atlassian Sourcetree Windows vulnerability
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before version 2.6.9 are affected by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13386?
CVE-2018-13386 has been classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-13386?
To mitigate CVE-2018-13386, update Atlassian Sourcetree to version 2.6.10 or later.
Who is affected by CVE-2018-13386?
CVE-2018-13386 affects users of Atlassian Sourcetree for Windows versions prior to 2.6.10.
What causes CVE-2018-13386?
CVE-2018-13386 is caused by an argument injection vulnerability that can be exploited via manipulated filenames in Mercurial repositories.
Is CVE-2018-13386 being actively exploited?
There is evidence that CVE-2018-13386 could be actively exploited if the vulnerable versions remain in use.