Vulnerabilities > Sonatype > Nexus Repository Manager
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-12 | CVE-2020-15868 | Incorrect Authorization vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. | 5.0 |
2020-04-27 | CVE-2020-11415 | Cleartext Storage of Sensitive Information vulnerability in Sonatype Nexus Repository Manager An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. | 4.0 |
2019-11-01 | CVE-2019-15588 | OS Command Injection vulnerability in Sonatype Nexus Repository Manager There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). | 9.0 |
2019-10-21 | CVE-2019-16530 | Unrestricted Upload of File with Dangerous Type vulnerability in Sonatype Nexus IQ Server Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution. | 9.0 |
2019-10-16 | CVE-2019-15893 | Unspecified vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution. | 6.5 |
2019-09-03 | CVE-2019-5475 | OS Command Injection vulnerability in Sonatype Nexus Repository Manager The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability. | 9.0 |
2019-08-22 | CVE-2019-14469 | Cross-site Scripting vulnerability in Sonatype Nexus Repository Manager In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS. | 3.5 |
2019-07-08 | CVE-2019-9630 | Incorrect Default Permissions vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images. | 5.0 |
2019-07-08 | CVE-2019-9629 | Improper Authentication vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials). | 7.5 |
2019-05-07 | CVE-2019-11629 | Cross-site Scripting vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS. | 4.3 |