HIGH🇵🇱 Wersja polska

CVE-2021-21373

CVSS 7.5v3.1pub. 2021-03-26upd. 2024-11-21

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL http://irclogs.nim-lang.org/packages.json. An attacker able to perform MitM can deliver a modified package list containing malicious software packages. If the packages are installed and used the attack escalates to untrusted code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
  • Nim Lang Nim

    APP
    Nim-Lang
    < 1.2.101.4.0 – 1.4.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-15690CRITICAL9.8PL ✓same product

CRLF Injection w bibliotece asyncftpclient języka Nim

CVE-2020-15692CRITICAL9.8PL ✓same product

Argument injection w bibliotece browsers w Nim 1.2.4 — wykonanie poleceń systemowych

CVE-2021-21372HIGH8.3same product

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 an...

CVE-2021-21374HIGH8.1same product

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 a...

CVE-2020-15694HIGH7.5same product

In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, htt...