PT-2021-20543 · Sonatype · Sonatype Nexus Repository Manager+1
Published
2021-06-17
·
Updated
2021-06-22
·
CVE-2021-34553
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Sonatype Nexus Repository Manager versions prior to 3.31.0
Description:
The issue allows a remote authenticated attacker to obtain a list of blob files and read the content of a blob file via a GET request without having the necessary access permissions. This is achieved by exploiting the lack of proper access control in the software.
Recommendations:
For versions prior to 3.31.0, update to version 3.31.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the blob files and implementing additional access controls to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus Repository Manager
Sonatype Nexus Repository Manager