Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2020-11753
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
0
Attacker Value
Unknown
CVE-2019-16530
Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
0
Attacker Value
Unknown
CVE-2019-15893
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2019-5475
Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
0
Attacker Value
Unknown
CVE-2019-15588
Disclosure Date: September 03, 2019 (last updated November 27, 2024)
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
0
Attacker Value
Unknown
CVE-2019-14469
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
0
Attacker Value
Unknown
CVE-2019-9630
Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
0
Attacker Value
Unknown
CVE-2019-9629
Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
0
Attacker Value
Unknown
CVE-2019-11629
Disclosure Date: May 07, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
0
Attacker Value
Unknown
CVE-2018-16619
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.14 allows XSS.
0