First published: Mon Jul 12 2021(Updated: )
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fossil | <2.14.2 | |
Fossil | >=2.15.0<2.15.2 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36377 has a medium severity level due to the potential for man-in-the-middle attacks resulting from the hostname validation issue.
To fix CVE-2021-36377, update Fossil to version 2.14.2 or 2.15.2 or later.
CVE-2021-36377 affects Fossil versions before 2.14.2 and 2.15.x before 2.15.2.
Yes, CVE-2021-36377 is relevant to the version of Fossil included in Fedora 34.
CVE-2021-36377 can lead to improper validation of TLS certificates, allowing for security risks in TLS connections.