Vulnerabilities (CVE)

Filtered by vendor Sonatype Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-11753 1 Sonatype 1 Nexus Repository Manager 3 2022-07-10 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
CVE-2020-10199 1 Sonatype 1 Nexus 2022-07-10 9.0 HIGH 8.8 HIGH
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
CVE-2020-10204 1 Sonatype 1 Nexus 2021-12-22 9.0 HIGH 7.2 HIGH
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
CVE-2021-40143 1 Sonatype 1 Nexus Repository Manager 3 2021-09-14 6.4 MEDIUM 8.2 HIGH
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
CVE-2020-15871 1 Sonatype 1 Nexus Repository Manager 3 2021-07-21 6.8 MEDIUM 8.8 HIGH
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
CVE-2020-15868 1 Sonatype 1 Nexus Repository Manager 2021-07-21 5.0 MEDIUM 7.5 HIGH
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
CVE-2018-16621 1 Sonatype 1 Nexus Repository Manager 2021-03-04 6.5 MEDIUM 7.2 HIGH
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
CVE-2020-15012 1 Sonatype 1 Nexus Repository Manager 2020-10-21 7.8 HIGH 8.6 HIGH
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
CVE-2018-16620 1 Sonatype 1 Nexus Repository Manager 2020-08-24 5.0 MEDIUM 7.5 HIGH
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
CVE-2019-15893 1 Sonatype 1 Nexus Repository Manager 2020-08-24 6.5 MEDIUM 7.2 HIGH
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
CVE-2019-9630 1 Sonatype 1 Nexus Repository Manager 2020-08-24 5.0 MEDIUM 7.5 HIGH
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
CVE-2020-11444 1 Sonatype 1 Nexus 2020-04-07 6.5 MEDIUM 8.8 HIGH
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
CVE-2019-15588 1 Sonatype 1 Nexus Repository Manager 2019-11-06 9.0 HIGH 7.2 HIGH
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
CVE-2019-16530 1 Sonatype 2 Nexus Iq Server, Nexus Repository Manager 2019-10-22 9.0 HIGH 7.2 HIGH
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
CVE-2019-5475 1 Sonatype 1 Nexus Repository Manager 2019-10-09 9.0 HIGH 8.8 HIGH
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.