ZeroHour

CVE-2020-29436

CVSS 3.1
6.5 medium
EPSS
1%p72
Published
()
Modified
Description

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.

Vendors
sonatype
Products
nexus repository manager
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.