Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
http://openwall.com/lists/oss-security/2017/12/17/3 | issue tracking mailing list release notes |