Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Is SourceTree affeceted by CVE-2022-24826 "Git LFS vulnerability" ?

Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 24, 2022

Atlassian,

Is SourceTree affeceted by CVE-2022-24826 "Git LFS vulnerability" ?

4 answers

2 accepted

0 votes
Answer accepted
Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 7, 2022

I questioned about this to Atlassian and got as below;

It is resolved by latest Git 2.36.0 and Git LFS v3.1.4 and in Sourcetree we have also updated and will be released with SourceTree 3.4.9.

0 votes
Answer accepted
Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 24, 2022

And Bamboo for WIndows too?

Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 25, 2022
0 votes
Vipin Yadav
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 28, 2022

It is resolved by latest Git 2.36.0 and Git LFS v3.1.4 and in Sourcetree we have also updated and will be released with SourceTree 3.4.9. 

Screenshot 2022-04-28 182004.png

Chihara
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
May 1, 2022

Vipin,

Thank you.

Will Atlassian also release Bamboo for WIndows for CVE-2022-24826 like BAM-21284 and BAM-21267?

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 25, 2022

Both applications use the git that is installed on the operating system that they are being run on.  You'll need to look at the version of git affected, not the applications.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events