Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
References
Link | Resource |
---|---|
https://support.sonatype.com | Vendor Advisory |
https://support.sonatype.com/hc/en-us/articles/4408801690515-CVE-2021-42568-Nexus-Repository-Manager-3-Incorrect-Access-Control-October-27-2021 | Vendor Advisory |
Configurations
Information
Published : 2021-11-02 06:15
Updated : 2021-11-08 07:07
NVD link : CVE-2021-42568
Mitre link : CVE-2021-42568
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
sonatype
- nexus_repository_manager