Description
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set nexus.scripts.allowCreation=false, undermining the expectation that this setting fully blocks script execution.
Remediation
References
Related Vulnerabilities
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-41800)
Drupal Core 8.5.x Multiple Vulnerabilities (8.5.0 - 8.5.14)
Squid Other Vulnerability (CVE-2010-3072)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5341)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2020-14340)