CVE-2020-11415
MEDIUMSonatype Nexus Repository Manager 2.0-2.14.16 - Cleartext Storage of Sensitive LDAP Credentials
Title source: llmDescription
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://support.sonatype.com/hc/en-us/articles/360045360854
Scores
CVSS v3
4.9
EPSS
0.0065
EPSS Percentile
46.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (1)
sonatype/nexus_repository_manager
2.0 - 2.14.17
Published
Apr 27, 2020
Tracked Since
Feb 18, 2026