[Bug 1185084] VUL-0: CVE-2021-21373: nim: "nimble refresh" falls back to a non-TLS URL in case of errror