CVE-2021-29158: Medium severity sonatype nexus repository 3 vulnerability
Published Apr 23, 2021
·Updated
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
Affected Software
1 affected component
Sonatype Nexus Repository Manager 3<=3.30.0
Remediation
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
Description
Frequently Asked Questions
1
What is CVE-2021-29158?
CVE-2021-29158 refers to a vulnerability in Sonatype Nexus Repository Manager 3 Pro up to and including version 3.30.0, which allows for incorrect access control.
2
How severe is CVE-2021-29158?
CVE-2021-29158 has a severity rating of medium with a severity value of 4.9.
3
Which software versions are affected by CVE-2021-29158?
Sonatype Nexus Repository Manager 3 Pro versions up to and including 3.30.0 are affected by CVE-2021-29158.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-29158?
The CWE ID for CVE-2021-29158 is CWE-863.
5
How can I fix CVE-2021-29158?
To fix CVE-2021-29158, it is recommended to update Sonatype Nexus Repository Manager 3 Pro to a version higher than 3.30.0.