CVE-2021-36377: High severity fossil vulnerability
Published Jul 12, 2021
·Updated
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Affected Software
3 affected components
Fossil-scm Fossil<2.14.2
Fossil-scm Fossil>=2.15.0<2.15.2
Fedoraproject Fedora=34
Event History
Jul 12, 2021
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-36377?
CVE-2021-36377 has a medium severity level due to the potential for man-in-the-middle attacks resulting from the hostname validation issue.
2
How do I fix CVE-2021-36377?
To fix CVE-2021-36377, update Fossil to version 2.14.2 or 2.15.2 or later.
3
Which versions of Fossil are affected by CVE-2021-36377?
CVE-2021-36377 affects Fossil versions before 2.14.2 and 2.15.x before 2.15.2.
4
Can CVE-2021-36377 be exploited on Fedora 34?
Yes, CVE-2021-36377 is relevant to the version of Fossil included in Fedora 34.
5
What impact does CVE-2021-36377 have on TLS connections?
CVE-2021-36377 can lead to improper validation of TLS certificates, allowing for security risks in TLS connections.