PT-2021-14455 · Nimble+3 · Nimble+3

Federico Ceratto

+1

·

Published

2021-03-26

·

Updated

2024-06-15

·

CVE-2021-21372

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nim versions prior to 1.2.10 Nim versions prior to 1.4.4
Description The issue concerns Nimble, a package manager for the Nim programming language. In affected versions, Nimble's doCmd can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.
Recommendations For versions prior to 1.2.10, update to version 1.2.10 or later. For versions prior to 1.4.4, update to version 1.4.4 or later.

Exploit

Fix

Special Elements Injection

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1770
CVE-2021-21372
GHSA-RG9F-W24H-962P
OPENSUSE-SU-2021:0618-1
OPENSUSE-SU-2021:0628-1
OPENSUSE-SU-2021_0618-1
OPENSUSE-SU-2022:10095-1
OPENSUSE-SU-2022:10101-1
OPENSUSE-SU-2024:11093-1

Affected Products

Alt Linux
Nim
Nimble
Suse