An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nexus_repository_manager | Sonatype | 2.0 (including) | 2.14.17 (excluding) |
Nexus_repository_manager | Sonatype | 3.0 (including) | 3.22.1 (excluding) |