CVE-2018-13385
CVE-2018-13385
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 2.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 jul 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2 before 2.7.6 are affected by this vulnerability.
Productos afectados
Atlassian · Sourcetree for macOS¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →