Description
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Remediation
References
Related Vulnerabilities
Vanilla Forums Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2018-15833)
Microsoft SQL Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5090)
Apache HTTP Server Other Vulnerability (CVE-2002-0061)
WordPress Plugin Google Analytics Opt-Out Cross-Site Scripting (2.3.4)