Description
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Remediation
References
Related Vulnerabilities
MediaWiki Improper Privilege Management Vulnerability (CVE-2020-10534)
WordPress Plugin Download Manager Arbitrary File Deletion (3.2.50)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2001-1247)
WordPress Plugin Ninja Announcements Lite 'ninja_annc.php' SQL Injection (1.2.3)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-6832)