Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype nexus repository manager 3 vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2021-43293
Sonatype Nexus Repository Manager 3.x prior to 3.36.0 allows a remote authenticated malicious user to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Sonatype Nexus Repository Manager
383
VMScore
CVE-2018-5306
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x prior to 3.8 allow remote malicious users to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/...
Sonatype Nexus Repository Manager
356
VMScore
CVE-2020-11415
An issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.17 and 3.x prior to 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Sonatype Nexus Repository Manager
490
VMScore
CVE-2020-29436
Sonatype Nexus Repository Manager 3.x prior to 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Sonatype Nexus Repository Manager
312
VMScore
CVE-2021-37152
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 prior to 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Sonatype Nexus Repository Manager
445
VMScore
CVE-2021-30635
Sonatype Nexus Repository Manager 3.x prior to 3.30.1 allows a remote malicious user to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Sonatype Nexus Repository Manager
356
VMScore
CVE-2021-34553
Sonatype Nexus Repository Manager 3.x prior to 3.31.0 allows a remote authenticated malicious user to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Sonatype Nexus Repository Manager
383
VMScore
CVE-2021-29159
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x prior to 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of t...
Sonatype Nexus Repository Manager
383
VMScore
CVE-2018-5307
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x prior to 2.14.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDeta...
Sonatype Nexus Repository Manager
580
VMScore
CVE-2020-11444
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Sonatype Nexus
3 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2