Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-225j-rc3h-9r34

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-22