First published: Mon Oct 12 2020(Updated: )
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonatype Nexus Repository Manager | >=2.0<2.14.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15012 is a Directory Traversal issue discovered in Sonatype Nexus Repository Manager 2.x before version 2.14.19.
CVE-2020-15012 allows a user to traverse up the file system and access content on disk that the user running nxrm also has access to.
The severity of CVE-2020-15012 is high, with a CVSS score of 8.6.
To fix CVE-2020-15012, update your Sonatype Nexus Repository Manager to version 2.14.19 or higher.
More information about CVE-2020-15012 can be found at the following reference link: https://support.sonatype.com/hc/en-us/articles/360051068253