Atlassian SourceTree 2.5c Client URL Handler Command Injection
Posted by deepcore on May 5, 2017 – 8:31 pm
Atlassian SourceTree Client version 2.5c and prior contain a client URL handler command injection vulnerability that allows attackers to execute specially crafted sourcetree:// commands with arbitrary arguments on multiple platforms.
Post a reply
You must be logged in to post a comment.