First published: Mon Apr 27 2020(Updated: )
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonatype Nexus Repository Manager | >=2.0<2.14.17 | |
Sonatype Nexus Repository Manager | >=3.0<3.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11415 is a vulnerability in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1 that allows admin users to retrieve the LDAP server system username/password in cleartext.
CVE-2020-11415 has a severity of 4.9 (medium).
CVE-2020-11415 affects Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1.
To fix CVE-2020-11415, you should update Sonatype Nexus Repository Manager to version 2.14.17 or later for 2.x, or version 3.22.1 or later for 3.x.
You can find more information about CVE-2020-11415 at the following link: [https://support.sonatype.com/hc/en-us/articles/360045360854](https://support.sonatype.com/hc/en-us/articles/360045360854)