Lucene search

K
cvelistAtlassianCVELIST:CVE-2018-5226
HistoryApr 25, 2018 - 9:00 p.m.

CVE-2018-5226

2018-04-2521:00:00
atlassian
www.cve.org
8

AI Score

9

Confidence

High

EPSS

0.001

Percentile

41.8%

There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions of Sourcetree for Windows before 2.5.5.0 are affected by this vulnerability.

CNA Affected

[
  {
    "product": "SourceTree Windows",
    "vendor": "Atlassian",
    "versions": [
      {
        "lessThan": "2.5.5.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9

Confidence

High

EPSS

0.001

Percentile

41.8%

Related for CVELIST:CVE-2018-5226