Skip to main content

Vendor/product archive

sonatype / nexus CVEs

Beta · best-effort

8 CVEs tagged to sonatype / nexus0 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-24622

Published Aug 25, 2020

In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11444

Published Apr 2, 2020

Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10204

Published Apr 1, 2020

Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

CVSS 7.2 · High
Buzz score
5.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-10199

Published Apr 1, 2020

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

CVSS 8.8 · High
Buzz score
29.9
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2014-9389

Published Jan 5, 2015

Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2034

Published Apr 1, 2014

Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0792

Published Jan 17, 2014

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintend…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1