Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown

CVE-2020-11753

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
Attacker Value
Unknown

CVE-2019-16530

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Attacker Value
Unknown

CVE-2019-15893

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
Attacker Value
Unknown

CVE-2019-5475

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
0
Attacker Value
Unknown

CVE-2019-15588

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
Attacker Value
Unknown

CVE-2019-14469

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
0
Attacker Value
Unknown

CVE-2019-9630

Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
0
Attacker Value
Unknown

CVE-2019-9629

Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
0
Attacker Value
Unknown

CVE-2019-11629

Disclosure Date: May 07, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
0
Attacker Value
Unknown

CVE-2018-16619

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.14 allows XSS.
0