Description
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Improper Locking Vulnerability (CVE-2009-2699)
Joomla Improper Input Validation Vulnerability (CVE-2020-10240)
MySQL Improper Initialization Vulnerability (CVE-2020-11655)
Magento CVE-2021-36021 Vulnerability (CVE-2021-36021)
Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470)