Description
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14632 Vulnerability (CVE-2020-14632)
WordPress Plugin WP Super Cache Multiple Vulnerabilities (1.4.4)
Claroline Other Vulnerability (CVE-2006-2284)
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51489)
WordPress Plugin Subscribe To Comments Reloaded Cross-Site Scripting (150611)