Description
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2895 Vulnerability (CVE-2020-2895)
WordPress Improper Privilege Management Vulnerability (CVE-2019-20043)
WordPress Plugin Advanced Booking Calendar SQL Injection (1.6.1)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1153)
phpList Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-3188)