Atlassian
Atlassian Sourcetree: vulnerabilidades y CVE
Atlassian Sourcetree tiene 16 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21575 | Alta (8) | 0.59% | — | 21 jul 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release… |
| CVE-2025-22165 | Media (5.9) | 0.13% | — | 24 jul 2025 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally… |
| CVE-2024-21697 | Alta (8.8) | 0.74% | — | 19 nov 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS… |
| CVE-2023-22514 | Alta (7.8) | 0.39% | — | 16 ene 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release… |
| CVE-2019-11582 | Alta (8.8) | 4.9% | — | 14 jun 2019 | An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI. |
| CVE-2018-20236 | Alta (8.8) | 6.4% | — | 8 mar 2019 | There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to… |
| CVE-2018-20235 | Alta (8.8) | 6.7% | — | 8 mar 2019 | There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a… |
| CVE-2018-20234 | Alta (8.8) | 5.9% | — | 8 mar 2019 | There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial… |
| CVE-2018-13397 | Alta (8.8) | 1.9% | — | 5 nov 2018 | There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial… |
| CVE-2018-13396 | Alta (8.8) | 1.9% | — | 5 nov 2018 | There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial… |
| CVE-2018-13386 | Alta (8.1) | 1.6% | — | 24 jul 2018 | There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able… |
| CVE-2018-13385 | Crítica (9.8) | 2.2% | — | 24 jul 2018 | There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to… |
| CVE-2018-5226 | Alta (8.8) | 1.5% | — | 25 abr 2018 | There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in… |
| CVE-2017-14593 | Alta (8.8) | 5.5% | — | 26 ene 2018 | Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit… |
| CVE-2017-14592 | Alta (8.8) | 5.5% | — | 26 ene 2018 | Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this… |
| CVE-2017-8768 | Crítica (9.8) | 8.3% | — | 4 may 2017 | Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext::… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.