Description
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group blobstore, an action that should require the nexus:blobstores:update permission instead. This could result in unauthorized modification of blobstore configuration without administrator
Remediation
References
Related Vulnerabilities
WordPress Plugin Header Footer Code Manager Cross-Site Scripting (1.1.16)
WordPress Plugin Related Sites 'guid' Parameter SQL Injection (2.1)
WordPress Plugin Multi Step Form Multiple Cross-Site Scripting Vulnerabilities (1.2.5)
SharePoint CVE-2021-1716 Vulnerability (CVE-2021-1716)
WordPress Plugin GraceMedia Media Player Local File Inclusion (1.0)