Vulnerabilities > Sonatype > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-10-16 | CVE-2019-15893 | Unspecified vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution. | 7.2 |
2019-09-03 | CVE-2019-5475 | OS Command Injection vulnerability in Sonatype Nexus Repository Manager The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability. | 8.8 |
2019-07-08 | CVE-2019-9630 | Incorrect Default Permissions vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images. | 7.5 |
2018-11-15 | CVE-2018-16621 | Expression Language Injection vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection. | 7.2 |
2018-11-15 | CVE-2018-16620 | Incorrect Authorization vulnerability in Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. | 7.5 |