Issue:
Per https://nvd.nist.gov/vuln/detail/CVE-2017-8768 the vulnerability is in the custom URL command handler.
I had 1.9.13 installed (on Windows 10), and then installed 2.0.20.1.
Installing 2.0.20.1:
- DOES NOT uninstall v1.9.x
- DOES NOT remove or change the registry entry that defines the command handler (HKEY_CLASSES_ROOT\sourcetree)
So the dangerous custom url handler still runs, and still loads the vulnerable v1.9.x despite the installation of v2.0.20.1.
Unless you manually uninstall 1.x, it seems that this vulnerability still exists!
I hope this is just something unusual with my setup, but I've tried un-installing and re-installing 2.20.0.1 and the same issue persists,
The security warning email and page say:
"Customers who have upgraded to SourceTree for Mac version 2.5.1 or SourceTree for Windows version 2.0.20.1 are not affected."
This does not appear to be true. To be true it would need to add "and have manually uninstalled all 1.x".
Comments
Some comments on the limited attempts made to notify the user:
- starting the very latest 1.19.x says "this is not supported".
- "Not supported" does not mean "is vulnerable and must be uninstalled"!. This warning needs to be much stronger!
- This version updated with this message should have removed the command handler registry entry to at least reduce the risk
- starting 2.0.20.1 says "these old versions were found and it's recommened they be uninstalled"
- Again, no mention of critical vulnerabilities. This should be much stronger!
- Even if 2.0.20.x can't uninstall the old versions automatically, it can at least delete or overwrite the registry entry that defines the command handler.
Test Case
To test this for yourself:
1. Create a new html file with contents such as:
<html>
<head>
</head>
<body>
<a href="sourcetree://vulnerability">Is this still vulnerable</a>
</body>
</html>
2. Open the html file in a browser and click the link. If SourceTree 1.9.x opens you are likely still vulnerable
Postscript
I realise SourceTree is free and you are presumably under lots of pressure over the last few days, so I do want to say thanks for the hard work and I hope these issues can be resolved quickly.
I don't believe anything in this discusses security issues that are not already in the public domain (or trivially related to it). If you disagree, please feel free to remove this comment and point me at your security contact.