Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24614.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.10.2"
}
]
},
{
"events": [
{
"introduced": "2.11.0"
},
{
"fixed": "2.11.2"
}
]
},
{
"events": [
{
"introduced": "2.12.0"
},
{
"fixed": "2.12.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-sp2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.2"
}
]
}
]