← back
CVE-2017-14592

CVE-2017-14592

EPSS 5.5%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 5.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Jan 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. From version 1.4.0 of Sourcetree for macOS, this vulnerability can be triggered from a webpage through the use of the Sourcetree URI handler. Versions of Sourcetree for macOS starting with 1.0b2 before version 2.7.0 are affected by this vulnerability.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →