Description
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
3.0.0 (semver) before 3.93.0
Credits
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc.
References
help.sonatype.com/...us-repository-3-93-0-release-notes.html
support.sonatype.com/hc/en-us/articles/52482870409491