Show filters
47 Total Results
Displaying 31-40 of 47
Sort by:
Attacker Value
Unknown

CVE-2019-5475

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
0
Attacker Value
Unknown

CVE-2019-15588

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
Attacker Value
Unknown

CVE-2019-14469

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
0
Attacker Value
Unknown

CVE-2019-9630

Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
0
Attacker Value
Unknown

CVE-2019-9629

Disclosure Date: July 08, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
0
Attacker Value
Unknown

CVE-2019-11629

Disclosure Date: May 07, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
0
Attacker Value
Unknown

CVE-2019-7238

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
0
Attacker Value
Unknown

CVE-2018-16619

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.14 allows XSS.
0
Attacker Value
Unknown

CVE-2018-16620

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
0
Attacker Value
Unknown

CVE-2018-16621

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.