7.5
CVSSv3

CVE-2021-36377

Published: 12/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Fossil prior to 2.14.2 and 2.15.x prior to 2.15.2 often skips the hostname check during TLS certificate validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fossil-scm fossil

fedoraproject fedora 34

Vendor Advisories

Fossil before version 2152 often skips the hostname check during TLS certificate validation ...