Description
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
3.0.0 (semver)
Credits
Erick Fernando Xavier de Oliveira (erickfernandox)
References
support.sonatype.com/hc/en-us/articles/29416509323923