Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown

CVE-2021-29159

Disclosure Date: April 28, 2021 (last updated November 28, 2024)
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
Attacker Value
Unknown

CVE-2021-30635

Disclosure Date: April 27, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Attacker Value
Unknown

CVE-2021-29158

Disclosure Date: April 23, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2020-29436

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Attacker Value
Unknown

CVE-2020-15012

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Attacker Value
Unknown

CVE-2020-15868

Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2020-15870

Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
Attacker Value
Unknown

CVE-2020-15871

Disclosure Date: July 31, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
Attacker Value
Unknown

CVE-2020-15869

Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
Attacker Value
Unknown

CVE-2020-11415

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.