CVE-2018-20234: Critical severity Atlassian Sourcetree Macos vulnerability
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20234?
CVE-2018-20234 is rated as a high severity vulnerability due to the potential for remote code execution.
What versions of Atlassian Sourcetree are affected by CVE-2018-20234?
CVE-2018-20234 affects Atlassian Sourcetree for macOS versions from 1.2 up to, but not including, 3.1.1.
How do I fix CVE-2018-20234?
To fix CVE-2018-20234, upgrade Atlassian Sourcetree to version 3.1.1 or later.
What type of attack does CVE-2018-20234 enable?
CVE-2018-20234 enables remote attackers with commit permissions to execute arbitrary code on the victim's machine.
Is this vulnerability specific to any operating system?
Yes, CVE-2018-20234 is specifically a vulnerability in the macOS version of Atlassian Sourcetree.