CVE-2020-15870
https://notcve.org/view.php?id=CVE-2020-15870
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). Sonatype Nexus Repository Manager OSS/Pro versiones anteriores a 3.25.1, permiten un ataque de tipo XSS (Problema 2 de 2) • https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360051424754 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-11415
https://notcve.org/view.php?id=CVE-2020-11415
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext. Se detectó un problema en Sonatype Nexus Repository Manager versiones 2.x versiones anteriores a 2.14.17 y versiones 3.x versiones anteriores a 3.22.1. Los usuarios administradores pueden recuperar el nombre de usuario y contraseña del sistema del servidor LDAP (tal como está configurado en nxrm) en texto sin cifrar. • https://support.sonatype.com/hc/en-us/articles/360045360854 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2020-11753
https://notcve.org/view.php?id=CVE-2020-11753
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable). Se descubrió un problema en Sonatype Nexus Repository Manager en las versiones 3.21.1 y 3.22.0. Es posible que un usuario con los privilegios apropiados cree, modifique y ejecute tareas scripting sin utilizar la Interfaz de Usuario o la API. • https://cwe.mitre.org/data/definitions/284.html https://support.sonatype.com/hc/en-us/articles/360046233714 • CWE-863: Incorrect Authorization •
CVE-2020-11444
https://notcve.org/view.php?id=CVE-2020-11444
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. Sonatype Nexus Repository Manager versiones 3.x hasta 3.21.2 incluyéndola, presenta un Control de Acceso Incorrecto. • https://github.com/zhzyker/CVE-2020-11444 https://github.com/CN016/Nexus-Repository-Manager-3-CVE-2020-11444- https://support.sonatype.com https://support.sonatype.com/hc/en-us/articles/360046133553 • CWE-276: Incorrect Default Permissions •
CVE-2020-10199 – Sonatype Nexus Repository Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10199
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). Sonatype Nexus Repository versiones anteriores a 3.21.2, permite una inyección JavaEL (problema 1 de 2). Sonatype Nexus version 3.21.1 suffers from an authenticated remote code execution vulnerability. Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. • https://www.exploit-db.com/exploits/49385 https://www.exploit-db.com/exploits/48343 https://github.com/jas502n/CVE-2020-10199 https://github.com/aleenzz/CVE-2020-10199 https://github.com/wsfengfan/CVE-2020-10199-10204 https://github.com/hugosg97/CVE-2020-10199-Nexus-3.21.01 http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html https:/ • CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') •