Vulnerabilities
Vulnerable Software
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
CVSS Score
4.3
EPSS Score
0.002
Published
2022-03-30
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
CVSS Score
4.3
EPSS Score
0.006
Published
2022-03-17
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).
CVSS Score
4.3
EPSS Score
0.001
Published
2021-11-04
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
CVSS Score
4.3
EPSS Score
0.001
Published
2021-11-02
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
CVSS Score
5.4
EPSS Score
0.069
Published
2021-08-10
Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
CVSS Score
4.3
EPSS Score
0.002
Published
2021-06-18
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
CVSS Score
6.1
EPSS Score
0.005
Published
2021-04-28
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
CVSS Score
5.3
EPSS Score
0.001
Published
2021-04-27
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
CVSS Score
6.5
EPSS Score
0.005
Published
2020-12-17
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
CVSS Score
8.6
EPSS Score
0.008
Published
2020-10-12


Contact Us

Shodan ® - All rights reserved