vendor

sonatype

33 thingsrelated by NVD

Its products

nexus repository manager 33

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly…
CVE-2026-77125
Severity high
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether…
CVE-2026-77124
Severity high
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the…
CVE-2026-77123
Severity medium
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus…
CVE-2026-77122
Severity medium
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata…
CVE-2026-77121
Severity medium
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration…
CVE-2026-17603
Severity high
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant…
CVE-2026-17601
Severity high
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's…
CVE-2026-17600
Severity high
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not…
CVE-2026-17599
Severity high
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or…
CVE-2026-17598
Severity medium
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user…
CVE-2026-17597
Severity low
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or…
CVE-2026-17596
Severity medium
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create…
CVE-2026-17595
Severity low
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the…
CVE-2026-17594
Severity medium
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy…
CVE-2026-17593
Severity high
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy…
CVE-2026-14646
Severity high
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP…
CVE-2026-14645
Severity medium
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to…
CVE-2026-14644
Severity high
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform…
CVE-2026-14504
Severity medium
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized…
CVE-2026-11403
Severity high
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating…
CVE-2026-10748
Severity high
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the…
CVE-2026-7494
Severity medium
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the…
CVE-2026-7308
Severity medium
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated…
CVE-2026-5189
Severity critical
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows…
CVE-2026-3438
Severity medium
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated…
CVE-2026-3199
Severity high
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1…
CVE-2026-3048
Severity low
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote…
CVE-2021-40143
Severity high
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
CVE-2021-29158
Severity medium
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
CVE-2020-15871
Severity high
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
CVE-2020-15870
Severity medium
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
CVE-2020-15869
Severity medium
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate…
CVE-2020-11753
Severity high