Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-03-26T21:20:15

Updated: 2021-03-26T21:20:15

Reserved: 2020-12-22T00:00:00


Link: CVE-2021-21372

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-26T22:15:12.697

Modified: 2022-10-24T17:14:16.087


Link: CVE-2021-21372

JSON object: View

cve-icon Redhat Information

No data.