Description
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.
Problem types
CWE-502 Deserialization of Untrusted Data
CWE-918 Server-Side Request Forgery (SSRF)
Product status
3.0.0 (semver) before 3.92.0
Credits
Icare (@Icare1337)
References
help.sonatype.com/...us-repository-3-92-0-release-notes.html
support.sonatype.com/hc/en-us/articles/51591695462675