PT-2023-12595 · Nim+2 · Nim+2

Araq

·

Published

2023-01-13

·

Updated

2023-06-03

·

CVE-2021-46872

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nim versions prior to 1.6.2 NimForum versions prior to 2.2.0
Description An issue in the RST module of the Nim language stdlib allows the javascript: URI scheme, potentially leading to XSS in some applications.
Recommendations For Nim versions prior to 1.6.2, update to version 1.6.2 or later to resolve the issue. For NimForum versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the RST module in the Nim language stdlib until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1935
CVE-2021-46872

Affected Products

Debian
Nim
Nimforum