Product
sonatype nexus repository manager
29 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-5764
CVE-2022-27907
CVE-2021-43961
CVE-2021-43293
CVE-2021-42568
CVE-2021-37152
CVE-2021-34553
CVE-2021-29159
CVE-2021-30635
CVE-2020-29436
CVE-2020-15012
CVE-2020-15868
CVE-2020-11415
CVE-2019-15588
CVE-2019-16530
CVE-2019-15893
CVE-2019-5475
CVE-2019-14469
CVE-2019-9630
CVE-2019-9629
CVE-2019-11629
CVE-2019-7238
CVE-2018-16621
CVE-2018-16620
CVE-2018-16619
CVE-2018-12100
CVE-2018-5307
CVE-2018-5306
CVE-2017-17717
>= 3.0.0 and < 3.73.0
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encryptin
>= 3.0.0 and < 3.38.0
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
>= 3.0.0 and < 3.38.0
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
>= 3.0.0 and <= 3.35.0
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumerat
>= 3.0.0 and <= 3.35.0
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-pr
>= 3.0.0 and < 3.33.0
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add
>= 3.0.0 and < 3.31.0
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read th
>= 3.23.0 and < 3.30.1
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a l
>= 3.0 and < 3.30.1
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in
>= 3.0.0 and < 3.29.0
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to
>= 2.0 and < 2.14.19
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted
< 3.26.0
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
>= 2.0 and < 2.14.17
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve th
<= 2.14.14
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remo
>= 2.0.0 and <= 2.14.14
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
< 2.14.15
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
>= 2.0 and <= 2.14.9-01
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are sup
>= 3.14.0 and <= 3.17.0
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
< 3.17.0
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repo
< 3.17.0
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
>= 2.0.0 and < 2.14.13
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
>= 3.0.0 and < 3.15.0
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
< 3.14.0
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
< 3.14.0
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
< 3.14.0
Sonatype Nexus Repository Manager before 3.14 allows XSS.
>= 3.3.0 and < 3.12.0
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
>= 2.0 and < 2.14.6
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote
>= 3.0 and < 3.8
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote at
<= 2.14.5
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integrati