Issue:
Per https://nvd.nist.gov/vuln/detail/CVE-2017-8768 the vulnerability is in the custom URL command handler.
I had 1.9.13 installed (on Windows 10), and then installed 2.0.20.1.
Installing 2.0.20.1:
So the dangerous custom url handler still runs, and still loads the vulnerable v1.9.x despite the installation of v2.0.20.1.
Unless you manually uninstall 1.x, it seems that this vulnerability still exists!
I hope this is just something unusual with my setup, but I've tried un-installing and re-installing 2.20.0.1 and the same issue persists,
The security warning email and page say:
"Customers who have upgraded to SourceTree for Mac version 2.5.1 or SourceTree for Windows version 2.0.20.1 are not affected."
This does not appear to be true. To be true it would need to add "and have manually uninstalled all 1.x".
Comments
Some comments on the limited attempts made to notify the user:
Test Case
To test this for yourself:
1. Create a new html file with contents such as:
<html> <head> </head> <body> <a href="sourcetree://vulnerability">Is this still vulnerable</a> </body> </html>
2. Open the html file in a browser and click the link. If SourceTree 1.9.x opens you are likely still vulnerable
Postscript
I realise SourceTree is free and you are presumably under lots of pressure over the last few days, so I do want to say thanks for the hard work and I hope these issues can be resolved quickly.
I don't believe anything in this discusses security issues that are not already in the public domain (or trivially related to it). If you disagree, please feel free to remove this comment and point me at your security contact.
Hi Richard, thanks for writing in and for the feedback. You're correct, manually removing older versions is required to close the security gap. We'll update our documents accordingly. Thank you for your thoughtful comments and proactive support.
-Rahul
Product Manager | SourceTree
PS. I'll comment on the support ticket as well.
Oh - also. This is the original bug on CVE-2017-8768, if you didn't look though already: https://jira.atlassian.com/browse/SRCTREEWIN-7161
Could be worth a comment on there.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
No problem. It seems worth flagging up.
For what it's worth, I think Atlassian would rather people came here first with most product related questions.
It's deliberately promoted as the first stop for users, partly because it filters out a lot of the trivial stuff before it goes to their support team (not that I am saying this is trivial!).
After all, me replying to you here is not costing them any money : )
Plus, there are some serious experts who post here with tons of experience in using Atlassian's products.
I agree that they could make the route to raise a bug more obvious. In general, there's quite a an array or resources and contact points available, so I'm never surprised when it is not clear.
I hope this new community is the first step toward improving that stuff. That's partly why I put the effort in here to help.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for taking this up Sam,
I have had response to other comments on here so I didn't realise there was somewhere else for more directly entering bugs. I'll go and add this bug via the link you recommend.
If you have contacts with Atlassian, its probably worth suggesting that they make the location for adding bug reports more clear; both in this section, and in the emails launching this community section. e.g. the email I received 3 days ago said:
"Get product support via the Q&A forum" (their bold)
so I hope I can be forgiven for posting in the wrong place!
That said, I do think it also has a place here as I feel it is important for other users to know the potential ongoing risk and how to protect themselves.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Richard - this is a community forum used (mostly) by users like you and me to share knowledge, tips and ask and answer questions.
Atlassian do read and post on here, but it's not a formal way to give feedback, raise bugs or request support.
If you want to contact Atlassian directly with a bug report like this, the best way is via a support ticket at https://support.atlassian.com/contact/
That'll get a bug raised on jira.atlassian.com.
In the meantime, I will see if I can bring this to the attention of someone from Atlassian.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.