6.8
CVSSv2

CVE-2021-21372

Published: 26/03/2021 Updated: 24/10/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Nimble is a package manager for the Nim programming language. In Nim release version prior to 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nim-lang nim

Vendor Advisories

Debian Bug report logs - #987272 CVE-2021-21372 CVE-2021-21373 CVE-2021-21374 Package: nim; Maintainer for nim is Federico Ceratto <federico@debianorg>; Source for nim is src:nim (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 20 Apr 2021 18:33:01 UTC Severity: important Tags: secu ...
In Nimble before version 0130, doCmd can be leveraged to execute arbitrary commands An attacker can craft a malicious entry in the packagesjson package list to trigger code execution ...