Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
| Software | From | Fixed in |
|---|---|---|
| fossil-scm / fossil | 2.12.0 | 2.12.1 |
| fossil-scm / fossil | 2.11.0 | 2.11.2 |
| fossil-scm / fossil | - | 2.10.2 |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| opensuse / leap | 15.1 | 15.1.x |
| opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
| opensuse / leap | 15.2 | 15.2.x |
| opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |