Nexus Repository 3 的 capability 读取 API 中存在敏感信息泄露漏洞。拥有 权限的账户可以获取在 webhook capability 中配置的明文共享密钥(shared secret),该密钥本应在所有 API 响应中隐藏(屏蔽)。此问题影响 Nexus Repository 3 的 3.2.0 至 3.95.x 版本,已在 3.96.0 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.2.0< 3.96.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.2.0 ~ 3.96.0 |
cpe:2.3:a:sonatype:nexus_repository_manager:3.2.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77124 | 7.5 HIGH | Nexus Repository 3 - Script Execution Disable Setting Not Enforced |
| CVE-2026-77125 | 7.1 HIGH | Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints |
| CVE-2026-77121 | 5.3 MEDIUM | Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields |
| CVE-2026-77122 | 5.3 MEDIUM | Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metada |
No comments yet