Nexus Repository Manager Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-15012 - Vulnerability Database

Nexus Repository Manager Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-15012

High
Reference: CVE-2020-15012
Title: Nexus Repository Manager Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).