Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
{ "binaries": [ { "binary_version": "1:2.10-1ubuntu0.1", "binary_name": "fossil" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-36377.json"
{ "binaries": [ { "binary_version": "1:2.18-1ubuntu0.1", "binary_name": "fossil" } ] }
{ "binaries": [ { "binary_version": "1:2.23-1ubuntu0.1", "binary_name": "fossil" } ] }
{ "binaries": [ { "binary_version": "1:2.26-2", "binary_name": "fossil" } ] }
{ "binaries": [ { "binary_version": "1:1.33-3ubuntu0.1~esm1", "binary_name": "fossil" } ] }
{ "binaries": [ { "binary_version": "1:2.5-1ubuntu0.1~esm1", "binary_name": "fossil" } ] }