CVE-2020-24622
MEDIUMSonatype Nexus Repository <3.26.1 - Info Disclosure
Title source: llmDescription
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Scores
CVSS v3
4.9
EPSS
0.0022
EPSS Percentile
44.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (1)
sonatype/nexus
< 3.27.0
Timeline
Published
Aug 25, 2020
Tracked Since
Feb 18, 2026