Description
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Remediation
References
Related Vulnerabilities
WordPress Plugin Pondol Carousel Cross-Site Scripting (1.0)
IBM WebSEAL Insertion of Sensitive Information into Log File Vulnerability (CVE-2017-1480)
WordPress Plugin Easy Forms for Mailchimp Unspecified Vulnerability (6.6.2)
MySQL CVE-2015-2566 Vulnerability (CVE-2015-2566)
WordPress Plugin WP-Forum 'forum_feed.php' SQL Injection (1.7.8)