Incorrect Access Control in Sonatype Nexus Repository Manager
CVE-2021-29158

4.9MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
23 April 2021

What is CVE-2021-29158?

Sonatype Nexus Repository Manager 3 Pro versions up to and including 3.30.0 are susceptible to a flaw related to incorrect access control. This vulnerability may allow unauthorized users to access restricted data or perform actions that should be limited to privileged accounts. Organizations utilizing this software need to ensure proper configurations and updates to mitigate potential security risks.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.