Show filters
47 Total Results
Displaying 11-20 of 47
Sort by:
Attacker Value
Unknown
CVE-2021-42568
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
0
Attacker Value
Unknown
CVE-2021-40143
Disclosure Date: September 07, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
0
Attacker Value
Unknown
CVE-2021-37152
Disclosure Date: August 10, 2021 (last updated November 28, 2024)
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
0
Attacker Value
Unknown
CVE-2021-34553
Disclosure Date: June 18, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
0
Attacker Value
Unknown
CVE-2021-29159
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
0
Attacker Value
Unknown
CVE-2021-30635
Disclosure Date: April 27, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
0
Attacker Value
Unknown
CVE-2021-29158
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2020-29436
Disclosure Date: December 17, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
0
Attacker Value
Unknown
CVE-2020-15012
Disclosure Date: October 12, 2020 (last updated November 28, 2024)
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
0
Attacker Value
Unknown
CVE-2020-24622
Disclosure Date: August 25, 2020 (last updated November 28, 2024)
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
0