CVE-2020-24614: Fedoraproject Fedora
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only
- Fossil-Scm Fossil: before 2.10.2 (fixed in 2.10.2); from 2.11.0, before 2.11.2 (fixed in 2.11.2); from 2.12.0, before 2.12.1 (fixed in 2.12.1)
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only; version 15.2 only
Published 2020-08-25. Last modified 2026-06-17.