Directory Traversal Vulnerability in Sonatype Nexus Repository Manager
CVE-2021-30635

5.3MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
27 April 2021

What is CVE-2021-30635?

A directory traversal vulnerability exists in Sonatype Nexus Repository Manager versions 3.x before 3.30.1, allowing remote attackers to enumerate files and directories in a UI-related folder. While this issue does not expose any customer-specific data, it could potentially aid attackers in crafting further exploits. Implementing the latest security updates is vital to mitigate risks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.