Vulnerabilities > Sonatype > Nexus > 3.0.0

DATE CVE VULNERABILITY TITLE RISK
2020-08-25 CVE-2020-24622 Insufficiently Protected Credentials vulnerability in Sonatype Nexus
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
network
low complexity
sonatype CWE-522
4.0
2020-04-02 CVE-2020-11444 Incorrect Default Permissions vulnerability in Sonatype Nexus
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
network
low complexity
sonatype CWE-276
6.5
2020-04-01 CVE-2020-10204 Improper Input Validation vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
network
low complexity
sonatype CWE-20
critical
9.0
2020-04-01 CVE-2020-10203 Cross-site Scripting vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows XSS.
network
sonatype CWE-79
3.5
2020-04-01 CVE-2020-10199 Expression Language Injection vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
network
low complexity
sonatype CWE-917
8.8
2019-03-21 CVE-2019-7238 Unspecified vulnerability in Sonatype Nexus
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
network
low complexity
sonatype
7.5