Upstream information

CVE-2020-15693 at MITRE

Description

In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.4
Vector AV:N/AC:L/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 6.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact Low
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1175333 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP3
  • nim >= 1.6.6-bp153.2.3.1
Patchnames:
openSUSE-2022-10095
SUSE Package Hub 15 SP4
  • nim >= 1.6.6-bp154.2.3.1
Patchnames:
openSUSE-2022-10101
openSUSE Leap 15.3
  • nim >= 1.6.6-bp153.2.3.1
Patchnames:
openSUSE-2022-10095
openSUSE Leap 15.4
  • nim >= 1.6.6-bp154.2.3.1
Patchnames:
openSUSE-2022-10101
openSUSE Tumbleweed
  • nim >= 1.6.6-3.1
Patchnames:
openSUSE Tumbleweed GA nim-1.6.6-3.1


SUSE Timeline for this CVE

CVE page created: Mon Aug 17 09:27:57 2020
CVE page last modified: Tue May 23 17:59:04 2023