CVE-2020-24614: High severity fossil vulnerability
Published Aug 25, 2020
·Updated
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
Affected Software
9 affected components
Fossil-scm Fossil<2.10.2
Fossil-scm Fossil>=2.11.0<2.11.2
Fossil-scm Fossil>=2.12.0<2.12.1
Fedoraproject Fedora=32
Fedoraproject Fedora=33
openSUSE Backports SLE=15.0-sp1
openSUSE Backports SLE=15.0-sp2
openSUSE Leap=15.1
openSUSE Leap=15.2
Event History
Aug 25, 2020
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24614?
CVE-2020-24614 is considered a critical vulnerability as it allows remote authenticated users to execute arbitrary code.
2
How do I fix CVE-2020-24614?
To fix CVE-2020-24614, upgrade Fossil to version 2.10.2, 2.11.2, or 2.12.1 or later.
3
Who is affected by CVE-2020-24614?
CVE-2020-24614 affects users with check-in privileges on Fossil repositories running vulnerable versions.
4
What versions of Fossil are vulnerable to CVE-2020-24614?
Fossil versions before 2.10.2, and versions 2.11.0 to 2.11.1, and 2.12.0 to 2.12.0 are vulnerable to CVE-2020-24614.
5
Can the exploitation of CVE-2020-24614 lead to system compromise?
Yes, exploitation of CVE-2020-24614 can lead to arbitrary code execution, potentially compromising the system.