Show filters
236 Total Results
Displaying 91-100 of 236
Sort by:
Attacker Value
Unknown

CVE-2021-34553

Disclosure Date: June 18, 2021 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Attacker Value
Unknown

CVE-2021-29159

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
Attacker Value
Unknown

CVE-2021-30635

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Attacker Value
Unknown

CVE-2021-29158

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2020-29436

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Attacker Value
Unknown

CVE-2020-15012

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Attacker Value
Unknown

CVE-2020-3597

Disclosure Date: October 07, 2020 (last updated February 22, 2025)
A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup files. An attacker could exploit this vulnerability by persuading an administrator to restore a crafted configuration backup file. A successful exploit could allow the attacker to overwrite arbitrary files that are accessible through the affected software on an affected device.
Attacker Value
Unknown

CVE-2020-24622

Disclosure Date: August 25, 2020 (last updated February 22, 2025)
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Attacker Value
Unknown

CVE-2020-24571

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
Attacker Value
Unknown

CVE-2020-15868

Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.