CVE-2017-17717: Critical severity Sonatype Nexus Repository Manager vulnerability
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17717?
CVE-2017-17717 refers to a vulnerability in Sonatype Nexus Repository Manager through version 2.14.5, which has weak password encryption with a hardcoded value in the LDAP integration feature.
What is the severity of CVE-2017-17717?
The severity of CVE-2017-17717 is critical with a severity value of 9.8.
How does CVE-2017-17717 affect Sonatype Nexus Repository Manager?
CVE-2017-17717 affects Sonatype Nexus Repository Manager through version 2.14.5 by exposing weak password encryption in the LDAP integration feature.
How can I fix the vulnerability identified by CVE-2017-17717?
To fix the vulnerability identified by CVE-2017-17717, you should update Sonatype Nexus Repository Manager to a version beyond 2.14.5 that addresses the weak password encryption issue.
Where can I find more information about CVE-2017-17717?
More information about CVE-2017-17717 can be found at the following link: http://openwall.com/lists/oss-security/2017/12/17/3