CVE-2021-36377

Name
CVE-2021-36377
Description
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://fossil-scm.org/forum/forumpost/8d367e16f53d93c789d70bd3bf2c9587227bbd5c6a7b8e512cccd79007536036
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JBTRZ5HCOUTIIKJF3T37NORI4P7EVYCY/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fossil-scm:fossil:*:*:*:*:*:*:*:* fossil >= None < 2.14.2
cpe:2.3:a:fossil-scm:fossil:*:*:*:*:*:*:*:* fossil >= 2.15.0 < 2.15.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
fossil 3.14-community 2.15.1-r0 David Demelier <markand@malikania.fr> possibly vulnerable