Impact
This vulnerability is a Remote Code Execution flaw that allows an authenticated attacker to run arbitrary code with high impact on confidentiality, integrity, and availability. The weakness is classified as CWE-94, indicating that invalid or malicious input can cause code compilation or execution within the application.
Affected Systems
Atlassian Sourcetree for Mac and Windows, version 3.4.11 is confirmed vulnerable. The CVE description indicates that the fix begins at release 3.4.13, so we infer that intermediate releases such as 3.4.12 are likely vulnerable, as they are before the fixed version and no explicit statement of remediation exists for them. The affected platforms are macOS and Windows, as indicated by the provided CPE taxonomy.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation at present. The vulnerability requires user interaction and authenticated access, implying that the attacker must have valid login credentials. It is not listed in the CISA KEV catalog, but vendors recommend immediate patching to mitigate the risk.
OpenCVE Enrichment