Greating,
I am new to sourcetree, I was checking it before installing it and I read about the command injection issue. I've also checked the question in this link:
I would like to know if this: SourceTreeSetup-2.0.20.1
is the latest and has the issue solved?
Thanks for your reply, I am really glad to hear.
I have one last question though: according to: https://www.cvedetails.com/vulnerability-list.php?vendor_id=3578
the version effected was 2.5c and prior, the one in SourceTree offical site is 2.0.20.1. This is confusing since 2.0 is prior to 2.5?
Thanks in advance,
Hi! For official information regarding the vulnerability, my recommendation is that you check our official source. You can find it at SourceTree Security Advisory.
Note that the site you linked is not even differentiating between Mac and Windows versions. Whilst this is not mentioned in that website, they're probably referring to the Mac version of SourceTree (which is currently 2.5.2).
Hope this clears your concerns :)
Ana
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi! Yes, SourceTree 2.0.20.1 is the latest one for Windows and it's not affected by the injection issue, it was fixed :)
Let us know if you need anything else!
Cheers,
Ana
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.