An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, b…
Medium CVSS 6.5
Summary
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html Release Notes
- https://support.sonatype.com/hc/en-us/articles/53137654741907 Vendor Advisory
Timeline
- nvd_ingest NVD