cbcvebase.
CVE-2020-24614
published 2020-08-25

CVE-2020-24614: Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have…

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.12%
86.4th percentile
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianfossil< fossil 1:2.12.1-1 (bookworm)fossil 1:2.12.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fossil-scmfossil< 2.10.22.10.2
fossil-scmfossil>= 0 < 1:2.12.1-11:2.12.1-1
fossil-scmfossil>= 0 < 1:2.12.1-11:2.12.1-1
fossil-scmfossil>= 0 < 1:2.12.1-11:2.12.1-1
fossil-scmfossil>= 2.11.0 < 2.11.22.11.2
fossil-scmfossil>= 2.12.0 < 2.12.12.12.1
opensusebackports_sle
opensuseleap
opensuseleap

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires the attacker to have check-in privileges on the Fossil repository; monitor for unexpected or unauthorized check-in activity by authenticated users.
  • The most serious RCE vector involves configuring the Fossil server in malicious ways; audit server configuration changes made by authenticated users.
  • Attack surface includes push operations; monitor and alert on push events from untrusted or newly-privileged authenticated users.
  • ·No public exploit code or specific attack payload details were available in the sources at time of disclosure; vulnerability details and related check-ins were placed under embargo.
  • ·There are no known vulnerabilities affecting servers from unauthenticated web users; exploitation is limited to users with a pre-existing trust relationship (site admin or check-in privileges).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.