In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24622
Reference (s):
- https://support.sonatype.com/hc/en-us/articles/360053516793
- https://issues.sonatype.org/browse/NEXUS-25019