CVE-2020-11415: Sonatype Nexus Repository Manager
Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Affected products
- Sonatype Nexus Repository Manager: from 2.0, before 2.14.17 (fixed in 2.14.17); from 3.0, before 3.22.1 (fixed in 3.22.1)
Published 2020-04-27. Last modified 2026-06-17.