sonatype-nexus-repository is vulnerable to Brute Force
87
High Risk
Sonatype Nexus Repository authentication endpoints for the UI and REST API do not restrict or throttle repeated failed login attempts. A remote unauthenticated attacker with network access to those endpoints can run unlimited credential-guessing or credential-stuffing attacks against user accounts and, on success, gain unauthorized access to artifacts, configuration, and stored credentials. The fix introduces authentication attempt rate limiting that returns HTTP 429 with a Retry-After header after consecutive failures, configurable via nexus.auth.ratelimit.* properties.
You are affected if you are using a version that falls within the vulnerable range and expose Nexus Repository authentication endpoints over the network.
sonatype-nexus-repository is vulnerable to Brute Force in versions 3.0.0 - 3.92.3.
Upgrade the com.sonatype.nexus.selfhosted.distributions:sonatype-nexus-repository library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.