Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
3.0.0 (semver)
affected
Description
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
3.0.0 (semver)
Credits
Erick Fernando Xavier de Oliveira (erickfernandox)
References
support.sonatype.com/hc/en-us/articles/29416509323923
support.sonatype.com/hc/en-us/articles/29416509323923