Description
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2019-2887 Vulnerability (CVE-2019-2887)
Oracle Database Server CVE-2019-2956 Vulnerability (CVE-2019-2956)
WordPress Plugin WP RSS By Publishers Multiple SQL Injection Vulnerabilities (0.1)
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress Remote Code Execution (1.3.4)