Description
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Remediation
References
Related Vulnerabilities
WordPress Plugin ARForms:Wordpress Form Builder Arbitrary File Deletion (3.7.1)
Envoy Proxy Incomplete Cleanup Vulnerability (CVE-2023-35945)
WordPress Plugin Navis DocumentCloud Cross-Site Scripting (0.1)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0701)