Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype nexus repository manager vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv2
CVE-2020-15012
A Directory Traversal issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Sonatype Nexus Repository Manager
5
CVSSv2
CVE-2020-15868
Sonatype Nexus Repository Manager OSS/Pro prior to 3.26.0 has Incorrect Access Control.
Sonatype Nexus Repository Manager
4.3
CVSSv2
CVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (issue 1 of 2).
Sonatype Nexus Repository Manager 3
6.8
CVSSv2
CVE-2020-15871
Sonatype Nexus Repository Manager OSS/Pro version prior to 3.25.1 allows Remote Code Execution.
Sonatype Nexus Repository Manager 3
4.3
CVSSv2
CVE-2020-15870
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (Issue 2 of 2).
Sonatype Nexus Repository Manager 3
4
CVSSv2
CVE-2020-11415
An issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.17 and 3.x prior to 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Sonatype Nexus Repository Manager
6.5
CVSSv2
CVE-2020-11753
An issue exists in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this no...
Sonatype Nexus Repository Manager 3 3.22.0
Sonatype Nexus Repository Manager 3 3.21.1
6.5
CVSSv2
CVE-2020-11444
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Sonatype Nexus
3 Github repositories
9
CVSSv2
CVE-2020-10199
Sonatype Nexus Repository prior to 3.21.2 allows JavaEL Injection (issue 1 of 2).
Sonatype Nexus
13 Github repositories
9
CVSSv2
CVE-2019-15588
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capabili...
Sonatype Nexus Repository Manager
2 Github repositories
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »