Regarding the command injection issue.

Greating,



I am new to sourcetree, I was checking it before installing it and I read about the command injection issue. I've also checked the question in this link: 


https://community.atlassian.com/t5/SourceTree-questions/More-info-on-the-Command-Injection-issue/qaq-p/585845





I would like to know if this: SourceTreeSetup-2.0.20.1

is the latest and has the issue solved?

2 answers

0 votes

Hi! Yes, SourceTree 2.0.20.1 is the latest one for Windows and it's not affected by the injection issue, it was fixed :)

Let us know if you need anything else!

Cheers,

Ana

Thanks for your reply, I am really glad to hear.



I have one last question though:

according to: https://www.cvedetails.com/vulnerability-list.php?vendor_id=3578



the version effected was 2.5c and prior, the one in SourceTree offical site is 2.0.20.1. This is confusing since 2.0 is prior to 2.5?





Thanks in advance,

Hi! For official information regarding the vulnerability, my recommendation is that you check our official source. You can find it at SourceTree Security Advisory.

Note that the site you linked is not even differentiating between Mac and Windows versions. Whilst this is not mentioned in that website, they're probably referring to the Mac version of SourceTree (which is currently 2.5.2).

Hope this clears your concerns :)

Ana

Yes, Thank you very much! =)

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Oct 23, 2018 in Sourcetree

Tip from the team: configure your repos for hosting goodness!

Supported Platforms macOS Windows We recently introduced support for additional hosting services such as GitHub Enterprise, GitLab (Cloud, Community Edition, Enterprise Edition), and...

832 views 3 2
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you