Vulnerabilities > Sonatype > Nexus > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-5764 Use of Hard-coded Credentials vulnerability in Sonatype Nexus
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others).
network
low complexity
sonatype CWE-798
6.5
2020-08-25 CVE-2020-24622 Insufficiently Protected Credentials vulnerability in Sonatype Nexus
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
network
low complexity
sonatype CWE-522
4.9
2020-04-01 CVE-2020-10203 Cross-site Scripting vulnerability in Sonatype Nexus
Sonatype Nexus Repository before 3.21.2 allows XSS.
network
low complexity
sonatype CWE-79
4.8