CVE-2020-15012
https://notcve.org/view.php?id=CVE-2020-15012
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to). Se detectó un problema de Salto de Directorio en Sonatype Nexus Repository Manager versiones 2.x anteriores a 2.14.19. Un usuario que requiere una ruta diseñada puede saltar el sistema de archivos para obtener acceso al contenido del disco (al que el usuario que ejecuta nxrm también tiene acceso) • https://support.sonatype.com/hc/en-us/articles/360051068253 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-24622
https://notcve.org/view.php?id=CVE-2020-24622
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. En Sonatype Nexus Repository versión 3.26.1, un usuario administrador puede exponer una clave secreta de S3 • https://issues.sonatype.org/browse/NEXUS-25019 https://support.sonatype.com/hc/en-us/articles/360053516793 • CWE-522: Insufficiently Protected Credentials •
CVE-2020-15868
https://notcve.org/view.php?id=CVE-2020-15868
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.26.0, presenta un Control de Acceso Incorrecto • https://support.sonatype.com/hc/en-us/articles/360052192533 •
CVE-2020-15871
https://notcve.org/view.php?id=CVE-2020-15871
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution. Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permite una ejecución de código remota • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360052192693 •
CVE-2020-15869
https://notcve.org/view.php?id=CVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permiten un ataque de tipo XSS (problema 1 de 2) • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360051424554 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •