← Voltar para CVEs
CVE-2022-23602
HIGH7.7
Descricao
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview" endpoint. Even if NimForum is running as a non-critical user, the forum.json secrets can be stolen. Version 2.2.0 of NimForum includes patches for this vulnerability. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.
Detalhes CVE
Pontuacao CVSS v3.17.7
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado2/1/2022
Ultima modificacao5/5/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
nim-lang:docutilsnim-lang:nimforum
Fraquezas (CWE)
CWE-22CWE-22
Referencias
https://github.com/nim-lang/Nim/commit/cb894c7094fb49014f85815a9dafc38b5dda743e(security-advisories@github.com)
https://github.com/nim-lang/nimforum/security/advisories/GHSA-q3vh-x957-wr75(security-advisories@github.com)
https://github.com/nim-lang/Nim/commit/cb894c7094fb49014f85815a9dafc38b5dda743e(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/nim-lang/nimforum/security/advisories/GHSA-q3vh-x957-wr75(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.