VendorsFossil-scmfossilany version
Vulnerabilities

Fossil-scm Fossil any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-24614
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
Published 2020-08-25 · Modified
8.8EPSS 0.031
CVE-2021-36377
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Published 2021-07-12 · Modified
7.5EPSS 0.006