Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown
CVE-2021-29159
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
0
Attacker Value
Unknown
CVE-2021-30635
Disclosure Date: April 27, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
0
Attacker Value
Unknown
CVE-2021-29158
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2020-29436
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
0
Attacker Value
Unknown
CVE-2020-15012
Disclosure Date: October 12, 2020 (last updated February 22, 2025)
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
0
Attacker Value
Unknown
CVE-2020-15868
Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2020-15870
Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
0
Attacker Value
Unknown
CVE-2020-15871
Disclosure Date: July 31, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2020-15869
Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2020-11415
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
0