PT-2021-23805 · Sonatype · Sonatype Nexus Repository Manager+1

Published

2021-11-04

·

Updated

2021-11-05

·

CVE-2021-43293

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository Manager versions prior to 3.36.0
Description The issue allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). This means an attacker could exploit the vulnerability to discover and map internal network services and systems.
Recommendations For versions prior to 3.36.0, update to version 3.36.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Nexus Repository Manager to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43293

Affected Products

Nexus Repository Manager
Sonatype Nexus Repository Manager