Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2020-10203
Sonatype Nexus Repository prior to 3.21.2 allows XSS.
Sonatype Nexus
4.3
CVSSv3
CVE-2022-27907
Sonatype Nexus Repository Manager 3.x prior to 3.38.0 allows SSRF.
Sonatype Nexus Repository Manager
8.8
CVSSv3
CVE-2019-5475
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Sonatype Nexus Repository Manager
4 Github repositories
4.3
CVSSv3
CVE-2021-34553
Sonatype Nexus Repository Manager 3.x prior to 3.31.0 allows a remote authenticated malicious user to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Sonatype Nexus Repository Manager
7.5
CVSSv3
CVE-2019-9630
Sonatype Nexus Repository Manager prior to 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Sonatype Nexus Repository Manager
6.5
CVSSv3
CVE-2020-29436
Sonatype Nexus Repository Manager 3.x prior to 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Sonatype Nexus Repository Manager
7.2
CVSSv3
CVE-2019-15893
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 allows Remote Code Execution.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-43961
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
Sonatype Nexus Repository Manager
5.4
CVSSv3
CVE-2019-14469
In Nexus Repository Manager prior to 3.18.0, users with elevated privileges can create stored XSS.
Sonatype Nexus Repository Manager
6.1
CVSSv3
CVE-2019-11629
Sonatype Nexus Repository Manager 2.x prior to 2.14.13 allows XSS.
Sonatype Nexus Repository Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »