CVE 5.1 MEDIUM

Nexus Repository 3 – Improper LDAP Referral Handling_CVE-2026-3048

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

Basic Information

ID CVE-2026-3048
Source Sonatype
Published May 11, 2026 at 17:11

Affected Product

Vendor Sonatype
Product Nexus Repository
Version 3.0.0
Affected Versions Sonatype Nexus Repository 3.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.