Page 4 of 37 results (0.005 seconds)

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to). Se detectó un problema de Salto de Directorio en Sonatype Nexus Repository Manager versiones 2.x anteriores a 2.14.19. Un usuario que requiere una ruta diseñada puede saltar el sistema de archivos para obtener acceso al contenido del disco (al que el usuario que ejecuta nxrm también tiene acceso) • https://support.sonatype.com/hc/en-us/articles/360051068253 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.26.0, presenta un Control de Acceso Incorrecto • https://support.sonatype.com/hc/en-us/articles/360052192533 •

CVSS: 8.8EPSS: 3%CPEs: 2EXPL: 0

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution. Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permite una ejecución de código remota • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360052192693 •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permiten un ataque de tipo XSS (problema 1 de 2) • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360051424554 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permiten un ataque de tipo XSS (Problema 2 de 2) • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360051424754 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •