CVE-2020-24622
Published Aug 25, 2020In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Vendor/product archive
8 CVEs tagged to sonatype / nexus — 0 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Sonatype Nexus Repository before 3.21.2 allows XSS.
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated e…
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintend…