Fossil-Scm Fossil vulnerabilities
4 known vulnerabilities affecting fossil-scm/fossil.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-34009MEDIUMCVSS 5.5v2.182022-07-28
CVE-2022-34009 [MEDIUM] CWE-79 CVE-2022-34009: Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS paylo
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.
nvd
CVE-2021-36377HIGHCVSS 7.5fixed in 2.14.2≥ 2.15.0, < 2.15.22021-07-12
CVE-2021-36377 [HIGH] CWE-295 CVE-2021-36377: Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
nvdosv
CVE-2020-24614HIGHCVSS 8.8fixed in 2.10.2≥ 2.11.0, < 2.11.2+1 more2020-08-25
CVE-2020-24614 [HIGH] CWE-862 CVE-2020-24614: Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated use
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
nvdosv
CVE-2017-17459CRITICALCVSS 9.8≥ 0, < 1:2.4-12017-12-07
CVE-2017-17459 [CRITICAL] CVE-2017-17459: http_transport
http_transport.c in Fossil before 2.4, when the SSH sync protocol is used, allows user-assisted remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-14176, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.
osv