In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NNim Lang Nim
APPNim-Lang≤ 1.2.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2020-15690CRITICAL9.8PL ✓same product
CRLF Injection w bibliotece asyncftpclient języka Nim
CVE-2020-15692CRITICAL9.8PL ✓same product
Argument injection w bibliotece browsers w Nim 1.2.4 — wykonanie poleceń systemowych
CVE-2021-21373HIGH7.5same product
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 a...
CVE-2021-21372HIGH8.3same product
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 an...
CVE-2021-21374HIGH8.1same product
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 a...