CVE-2021-30635

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/04/2021
Last modified:
04/05/2021

Description

Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:* 3.0 (including) 3.30.1 (excluding)


References to Advisories, Solutions, and Tools