CVE-2018-20236 is a vulnerability in Atlassian Sourcetree
Published on March 8, 2019
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.
Products Associated with CVE-2018-20236
Want to know whenever a new CVE is published for Atlassian Sourcetree? stack.watch will email you.
Affected Versions
Atlassian Sourcetree for Windows:- Version 0.5a and below unspecified is affected.
- Version unspecified and below 3.0.10 is affected.
Exploit Probability
EPSS
2.36%
Percentile
84.66%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.