PT-2021-14455 · Nimble+3 · Nimble+3
Federico Ceratto
+1
·
Published
2021-03-26
·
Updated
2024-06-15
·
CVE-2021-21372
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nim versions prior to 1.2.10
Nim versions prior to 1.4.4
Description
The issue concerns Nimble, a package manager for the Nim programming language. In affected versions, Nimble's doCmd can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the
packages.json package list to trigger code execution.Recommendations
For versions prior to 1.2.10, update to version 1.2.10 or later.
For versions prior to 1.4.4, update to version 1.4.4 or later.
Exploit
Fix
Special Elements Injection
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nim
Nimble
Suse