Vulnerabilities
Vulnerable Software
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
CVSS Score
4.3
EPSS Score
0.037
Published
2021-06-18
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
CVSS Score
5.3
EPSS Score
0.018
Published
2021-04-27
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
CVSS Score
6.5
EPSS Score
0.015
Published
2020-12-17
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
CVSS Score
4.9
EPSS Score
0.006
Published
2020-04-27


Contact Us

Shodan ® - All rights reserved