Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype nexus repository manager vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2021-30635
Sonatype Nexus Repository Manager 3.x prior to 3.30.1 allows a remote malicious user to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-43293
Sonatype Nexus Repository Manager 3.x prior to 3.36.0 allows a remote authenticated malicious user to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Sonatype Nexus Repository Manager
8.8
CVSSv3
CVE-2019-5475
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Sonatype Nexus Repository Manager
4 Github repositories
4.9
CVSSv3
CVE-2020-11415
An issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.17 and 3.x prior to 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Sonatype Nexus Repository Manager
6.1
CVSSv3
CVE-2018-16619
Sonatype Nexus Repository Manager prior to 3.14 allows XSS.
Sonatype Nexus Repository Manager
7.5
CVSSv3
CVE-2018-16620
Sonatype Nexus Repository Manager prior to 3.14 has Incorrect Access Control.
Sonatype Nexus Repository Manager
9.8
CVSSv3
CVE-2017-17717
Sonatype Nexus Repository Manager up to and including 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
Sonatype Nexus Repository Manager
7.2
CVSSv3
CVE-2019-15893
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 allows Remote Code Execution.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-34553
Sonatype Nexus Repository Manager 3.x prior to 3.31.0 allows a remote authenticated malicious user to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Sonatype Nexus Repository Manager
8.6
CVSSv3
CVE-2020-15012
A Directory Traversal issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Sonatype Nexus Repository Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-0044
client side
CVE-2021-47601
deserialization
CVE-2024-34994
encryption
CVE-2021-47609
CVE-2024-37079
CVE-2024-38608
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »