Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype vulnerabilities and exploits
(subscribe to this query)
9
CVSSv2
CVE-2020-10199
Sonatype Nexus Repository prior to 3.21.2 allows JavaEL Injection (issue 1 of 2).
Sonatype Nexus
13 Github repositories
3.5
CVSSv2
CVE-2020-10203
Sonatype Nexus Repository prior to 3.21.2 allows XSS.
Sonatype Nexus
9
CVSSv2
CVE-2020-10204
Sonatype Nexus Repository prior to 3.21.2 allows Remote Code Execution.
Sonatype Nexus
5 Github repositories
9
CVSSv2
CVE-2019-15588
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capabili...
Sonatype Nexus Repository Manager
2 Github repositories
9
CVSSv2
CVE-2019-16530
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 and 3.x prior to 3.19, and IQ Server prior to 72, has remote code execution.
Sonatype Nexus Repository Manager
Sonatype Nexus Iq Server
6.5
CVSSv2
CVE-2019-15893
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 allows Remote Code Execution.
Sonatype Nexus Repository Manager
9
CVSSv2
CVE-2019-5475
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Sonatype Nexus Repository Manager
4 Github repositories
3.5
CVSSv2
CVE-2019-14469
In Nexus Repository Manager prior to 3.18.0, users with elevated privileges can create stored XSS.
Sonatype Nexus Repository Manager
7.5
CVSSv2
CVE-2019-9629
Sonatype Nexus Repository Manager prior to 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
Sonatype Nexus Repository Manager
5
CVSSv2
CVE-2019-9630
Sonatype Nexus Repository Manager prior to 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
Sonatype Nexus Repository Manager
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »