Vulnerabilities > Sonatype > Nexus

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-5764 Use of Hard-coded Credentials vulnerability in Sonatype Nexus
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others).
network
low complexity
sonatype CWE-798
6.5
2020-08-25 CVE-2020-24622 Insufficiently Protected Credentials vulnerability in Sonatype Nexus
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
network
low complexity
sonatype CWE-522
4.9
2020-04-02 CVE-2020-11444 Incorrect Default Permissions vulnerability in Sonatype Nexus
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
network
low complexity
sonatype CWE-276
8.8
2020-04-01 CVE-2020-10204 Improper Input Validation vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
network
low complexity
sonatype CWE-20
7.2
2020-04-01 CVE-2020-10203 Cross-site Scripting vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows XSS.
network
low complexity
sonatype CWE-79
4.8
2020-04-01 CVE-2020-10199 Expression Language Injection vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
network
low complexity
sonatype CWE-917
8.8
2019-03-21 CVE-2019-7238 Unspecified vulnerability in Sonatype Nexus
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
network
low complexity
sonatype
critical
9.8