CVE-2019-11582

HIGH

Atlassian Sourcetree for Windows <3.1.3 - Command Injection

Title source: llm

Description

An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.

Scores

CVSS v3 8.8
EPSS 0.0188
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-88
Status published

Affected Products (1)

atlassian/sourcetree < 3.1.3

Timeline

Published Jun 14, 2019
Tracked Since Feb 18, 2026