Junglewise Threat Intelligence

CVE-2019-7238: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

CVE-2019-7238 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-12-10

Technologies: Sonatype Nexus Repository 3, Sonatype Nexus Repository Manager. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository Manager 3 versions prior to 3.15.0 contain an incorrect access control vulnerability. This flaw allows unauthenticated remote attackers to execute arbitrary code on the server.

Affected products

  • Sonatype Nexus Repository Manager 3 3.0.0 to 3.14.1

Timeline

  • 2019-02-05: disclosed: Vendor advisory published by Sonatype
  • 2019-03-21: disclosed: NVD Published Date
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats