PT-2021-8044 · Nimble+2 · Nimble+2
Tintinweb
·
Published
2021-02-04
·
Updated
2024-06-15
·
CVE-2021-21374
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nimble versions prior to 1.2.10
Nimble versions prior to 1.4.4
Description
The issue is related to the
nimble refresh function of the Nimble package manager for the Nim programming language. It is caused by the lack of verification of downloaded packages due to an error in the certificate authentication procedure. This can allow a remote attacker to perform a man-in-the-middle attack or execute arbitrary code by downloading malicious packages.Recommendations
For Nimble versions prior to 1.2.10, update to version 1.2.10 or later to resolve the issue.
For Nimble versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue.
As a temporary workaround, consider disabling the
nimble refresh function until a patch is available.
Restrict access to the httpClient to minimize the risk of exploitation.Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nimble
Suse