Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-03-26T21:20:15
Updated: 2024-08-03T18:09:15.920Z
Reserved: 2020-12-22T00:00:00
Link: CVE-2021-21372
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-26T22:15:12.697
Modified: 2024-11-21T05:48:13.240
Link: CVE-2021-21372
Redhat
No data.