Executive brief
Sonatype Nexus Repository Manager 3 versions prior to 3.15.0 contain an incorrect access control vulnerability. This flaw allows unauthenticated remote attackers to execute arbitrary code on the server.
Affected products
- Sonatype Nexus Repository Manager 3 3.0.0 to 3.14.1
Timeline
- 2019-02-05: disclosed: Vendor advisory published by Sonatype
- 2019-03-21: disclosed: NVD Published Date
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog