Good news ! Hackbusters community is waiting for you !  https://discuss.hackbusters.com
KnowBe4 has been running the HackBusters site for a few years now, providing you with trending IT security news. We are expanding it and have launched a new exciting online community! The forum is divided into four main topics or categories: Social Engineering, Ransomware, Phishing and Security Awareness Training. You are invited to be one of the first to join us at: https://discuss.hackbusters.com.

Code Execution Flaw Found in Sonatype Nexus Repository Manager

A critical remote code execution vulnerability has been found and patched in Sonatype’s Nexus Repository Manager (NXRM), a popular open-source tool that allows developers to manage software components.

The flaw, tracked as CVE-2019-7238, was reported to Sonatype by researchers from Chinese companies Chaitin Tech and Tencent. A patch was released by the vendor on January 11, and Trend Micro on Thursday released technical details on how the vulnerability can be exploited.

The researchers found that a weakness related to insufficient access controls in NXRM, specifically versions 3.6.2 OSS/Pro through 3.14.0, allows an unauthenticated attacker to remotely execute arbitrary code and programs on the host system by sending specially crafted requests. The security hole has been patched with the release of version 3.15.

The flaw has been classified as “critical” (CVSS score of 10) and Trend Micro warns that since it doesn’t require authentication it’s easier for malicious actors to...(continued)

View All Trending Stories