CVE-2020-24614Missing Authorization in Fossil

Severity
8.8HIGHNVD
EPSS
6.4%
top 8.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 24

Description

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDfossil-scm/fossil2.11.02.11.2+2
Debianfossil-scm/fossil< 1:2.12.1-1+2
NVDopensuse/leap15.1, 15.2+1

Also affects: Fedora 32, 33

🔴Vulnerability Details

3
GHSA
GHSA-83fw-5hmv-mmqf: Fossil before 22022-05-24
OSV
CVE-2020-24614: Fossil before 22020-08-25
CVEList
CVE-2020-24614: Fossil before 22020-08-25

📋Vendor Advisories

1
Debian
CVE-2020-24614: fossil - Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remo...2020

💬Community

2
Bugzilla
CVE-2020-24614 fossil: allows remote authenticated users to execute arbitrary code [fedora-all]2020-08-20
Bugzilla
CVE-2020-24614 fossil: allows remote authenticated users to execute arbitrary code2020-08-20
CVE-2020-24614 — Missing Authorization in Fossil | cvebase