在 Sonatype Nexus Repository 3 中发现了一个漏洞,其涉及两个用于 blobstore 组管理的 REST API 端点未正确执行预期的授权检查。仅被授予 权限的用户可以调用这些端点,将现有的 blobstore 转换为组 blobstore,而该操作本应要求 权限。这可能导致未经管理员批准,即可对 blobstore 配置进行未授权修改。 权限是一种具名权限,必须由管理员显式授予,并非默认拥有。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.19.0< 3.96.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.19.0 ~ 3.96.0 |
cpe:2.3:a:sonatype:nexus_repository_manager:3.19.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77124 | 7.5 HIGH | Nexus Repository 3 - Script Execution Disable Setting Not Enforced |
| CVE-2026-77123 | 6.0 MEDIUM | Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API |
| CVE-2026-77121 | 5.3 MEDIUM | Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields |
| CVE-2026-77122 | 5.3 MEDIUM | Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metada |
No comments yet