Description
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Security Bypass (3.2.0 - 3.4.4)
Dolibarr Incorrect Authorization Vulnerability (CVE-2020-12669)
Drupal Core 5.x Session Fixation (5.0 - 5.19)
WordPress Plugin WordPress Gallery-NextGEN Gallery Cross-Site Request Forgery (3.28)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Local File Inclusion (1.5.24)