Show filters
47 Total Results
Displaying 1-10 of 47
Sort by:
Attacker Value
Moderate
CVE-2020-10204
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2020-10199
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2024-5082
Disclosure Date: November 14, 2024 (last updated November 14, 2024)
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
0
Attacker Value
Unknown
CVE-2024-5083
Disclosure Date: November 14, 2024 (last updated November 14, 2024)
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
0
Attacker Value
Unknown
CVE-2024-5764
Disclosure Date: October 23, 2024 (last updated November 07, 2024)
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated.
This issue affects Nexus Repository: from 3.0.0 through 3.72.0.
0
Attacker Value
Unknown
CVE-2024-4956
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
0
Attacker Value
Unknown
CVE-2024-1142
Disclosure Date: March 21, 2024 (last updated March 21, 2024)
Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.
0
Attacker Value
Unknown
CVE-2022-27907
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
0
Attacker Value
Unknown
CVE-2021-43961
Disclosure Date: March 17, 2022 (last updated October 07, 2023)
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
0
Attacker Value
Unknown
CVE-2021-43293
Disclosure Date: November 04, 2021 (last updated November 28, 2024)
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).
0