Show filters
104 Total Results
Displaying 51-60 of 104
Sort by:
Attacker Value
Unknown
CVE-2020-29436
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
0
Attacker Value
Unknown
CVE-2020-8908
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
0
Attacker Value
Unknown
CVE-2020-25649
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
0
Attacker Value
Unknown
CVE-2020-15012
Disclosure Date: October 12, 2020 (last updated February 22, 2025)
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
0
Attacker Value
Unknown
CVE-2020-11998
Disclosure Date: September 10, 2020 (last updated November 08, 2023)
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13
0
Attacker Value
Unknown
CVE-2020-24616
Disclosure Date: August 25, 2020 (last updated February 22, 2025)
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
0
Attacker Value
Unknown
CVE-2020-15868
Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2020-15870
Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
0
Attacker Value
Unknown
CVE-2020-15871
Disclosure Date: July 31, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2020-15869
Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
0