CVE-2021-29495

Published
View on NVD ↗
CVSS v3
5.9
MEDIUM
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer" as documented.

Embargoed security issues that will be made public after a fix is made available. Use https://github.com/nim-lang/security/security
GitHubGitHub
5