Show filters
36 Total Results
Displaying 1-10 of 36
Sort by:
Attacker Value
Unknown
CVE-2024-5082
Disclosure Date: November 14, 2024 (last updated November 14, 2024)
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
0
Attacker Value
Unknown
CVE-2024-5083
Disclosure Date: November 14, 2024 (last updated November 14, 2024)
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
0
Attacker Value
Unknown
CVE-2024-4956
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
0
Attacker Value
Unknown
CVE-2022-27907
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
0
Attacker Value
Unknown
CVE-2021-43961
Disclosure Date: March 17, 2022 (last updated October 07, 2023)
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
0
Attacker Value
Unknown
CVE-2021-43293
Disclosure Date: November 04, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).
0
Attacker Value
Unknown
CVE-2021-42568
Disclosure Date: November 02, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
0
Attacker Value
Unknown
CVE-2021-40143
Disclosure Date: September 07, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
0
Attacker Value
Unknown
CVE-2021-37152
Disclosure Date: August 10, 2021 (last updated November 28, 2024)
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
0
Attacker Value
Unknown
CVE-2021-34553
Disclosure Date: June 18, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
0