漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nimble falls back to insecure http url when fetching packages
Vulnerability Description
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL http://irclogs.nim-lang.org/packages.json. An attacker able to perform MitM can deliver a modified package list containing malicious software packages. If the packages are installed and used the attack escalates to untrusted code execution.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
Vulnerability Type
使用不可信的源
Vulnerability Title
Nimble 信任管理问题漏洞
Vulnerability Description
Nimble是开源的Nim编程语言的软件包管理器。 Nimble before versions 1.2.10 and 1.4.4 存在信任管理问题漏洞,攻击者可利用该漏洞可以传递一个修改过的包含恶意软件包的包列表。如果安装并使用了软件包,攻击将升级为不受信任的代码执行。
CVSS Information
N/A
Vulnerability Type
N/A