This update for fossil fixes the following issues:
fossil 2.12.1:
CVE-2020-24614: Remote authenticated users with check-in or
administrative privileges could have executed arbitrary code
[boo#1175760]
Security fix in the 'fossil git export' command. New
'safety-net' features were added to prevent similar problems
in the future.
Enhancements to the graph display for cases when there are
many cherry-pick merges into a single check-in. Example
Enhance the fossil open command with the new --workdir option
and the ability to accept a URL as the repository name,
causing the remote repository to be cloned automatically. Do
not allow 'fossil open' to open in a non-empty working
directory unless the --keep option or the new --force option
is used.
Enhance the markdown formatter to more closely follow the
CommonMark specification with regard to text
highlighting. Underscores in the middle of identifiers (ex:
fossil_printf()) no longer need to be escaped.
The markdown-to-html translator can prevent unsafe HTML (for
example: