Description
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Remediation
References
Related Vulnerabilities
WordPress Plugin Jssor Slider Arbitrary File Upload (1.3)
Joomla Improper Access Control Vulnerability (CVE-2026-21629)
WordPress Plugin WP Prayer Cross-Site Request Forgery (1.5.4)
WordPress Plugin Uploader Cross-Site Scripting and Arbitrary File Upload Vulnerabilities (1.0.4)
WordPress Plugin MAZ Loader-Preloader Builder for WordPress Cross-Site Request Forgery (1.4.0)