First published: Tue Apr 27 2021(Updated: )
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonatype Nexus Repository Manager | >=3.0<3.30.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30635 is a vulnerability in Sonatype Nexus Repository Manager 3.x before 3.30.1 that allows a remote attacker to get a list of files and directories in a UI-related folder via directory traversal.
CVE-2021-30635 affects Sonatype Nexus Repository Manager 3.x versions before 3.30.1.
The severity of CVE-2021-30635 is medium with a CVSS score of 5.3.
To fix the CVE-2021-30635 vulnerability, it is recommended to update Sonatype Nexus Repository Manager to version 3.30.1 or later.
More information about CVE-2021-30635 can be found at the following reference: https://support.sonatype.com/hc/en-us/articles/1500006879561