CVE-2021-37152
https://notcve.org/view.php?id=CVE-2021-37152
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications. Se presentan múltiples problemas de tipo XSS en Sonatype Nexus Repository Manager 3 versiones anteriores a 3.33.0. Un atacante autenticado con la capacidad de añadir archivos HTML a un repositorio podría redirigir a usuarios a las páginas de Nexus Repository Manager con modificaciones de código • https://github.com/SecurityAnalysts/CVE-2021-37152 https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/4404115639827 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-34553
https://notcve.org/view.php?id=CVE-2021-34553
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access. Sonatype Nexus Repository Manager 3.x antes de la versión 3.31.0 permite a un atacante remoto autentificado obtener una lista de archivos blob y leer el contenido de un archivo blob (a través de una petición GET) sin haber recibido acceso • https://support.sonatype.com/hc/en-us/articles/4402433828371 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2021-29159
https://notcve.org/view.php?id=CVE-2021-29159
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application. Se detectó una vulnerabilidad de tipo cross-site scripting (XSS) en Nexus Repository Manager versiones 3.x anteriores a 3.30.1. Un atacante con una cuenta local puede crear entidades con propiedades diseñadas que, cuando es visulizada por un administrador, pueden ejecutar JavaScript arbitrario en el contexto de la aplicación NXRM • https://support.sonatype.com/hc/en-us/articles/1500005031082 https://support.sonatype.com/hc/en-us/categories/201980768-Welcome-to-the-Sonatype-Support-Knowledge-Base • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-30635
https://notcve.org/view.php?id=CVE-2021-30635
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed). Sonatype Nexus Repository Manager versiones 3.x anteriores a 3.30.1, permite a un atacante remoto obtener una lista de archivos y directorios que se presentan en una carpeta relacionada con la interfaz de usuario por medio de un salto de directorio (no es expuesto datos específicos del cliente) • https://support.sonatype.com/hc/en-us/articles/1500006879561 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2021-29158
https://notcve.org/view.php?id=CVE-2021-29158
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control. Sonatype Nexus Repository Manager 3 Pro versiones hasta 3.30.0 incluyéndola, presenta un Control de Acceso Incorrecto • https://support.sonatype.com/hc/en-us/articles/1500006126462 https://support.sonatype.com/hc/en-us/categories/201980768-Welcome-to-the-Sonatype-Support-Knowledge-Base • CWE-863: Incorrect Authorization •