CyberRota Analysis
AI-GeneratedNexus Repository 3 is vulnerable to a sensitive information disclosure issue within its capability read API, allowing accounts with the nexus:capabilities:read privilege to access plaintext shared secrets intended to be masked. This vulnerability impacts versions 3.2.0 through 3.95.x and could lead to unauthorized access to sensitive configuration data. Organizations using affected versions should prioritize upgrading to version 3.96.0 to mitigate potential security risks.
Original NVD Description
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0.