CVE-2021-29158

Executive Summary

Sonatype Nexus Repository Manager 3 Pro versions 3.0.0‑3.30.0 suffer from an incorrect access control flaw (CVE‑2021‑29158). The vulnerability allows authenticated users to bypass repository permissions and gain unauthorized read/write access to protected artifacts, potentially exposing sensitive code or enabling tampering. The issue is not yet listed in CISA KEV but should be mitigated by upgrading to 3.30.1 or later, applying the official patch, or restricting network access.


Authoritative CVE Metadata - CVSS Base Score: 4.9 (MEDIUM) - Published: 2021-04-23T21:15:08.280 - Last Modified: 2026-09-22T18:12:37.237

Original Description: Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

"A rolling stone gathers no moss."

— Publilius Syrus
Source: NVD