Sonatype
Sonatype Nexus Repository Manager: vulnerabilidades y CVE
Sonatype Nexus Repository Manager tiene 64 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE64
Últimos 12 meses29
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-7238 | Crítica (9.8) | 77% | ⚠ Explotación activa | 21 mar 2019 | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77125 | Alta (7.1) | 0.29% | — | 2 sept 2026 | A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the… |
| CVE-2026-77124 | Alta (7.5) | 0.72% | — | 2 sept 2026 | In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding… |
| CVE-2026-77123 | Media (6) | 0.46% | — | 2 sept 2026 | Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a… |
| CVE-2026-77122 | Media (5.3) | 0.28% | — | 2 sept 2026 | An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group… |
| CVE-2026-77121 | Media (5.3) | 0.25% | — | 2 sept 2026 | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components… |
| CVE-2026-17603 | Alta (8.7) | 0.48% | — | 7 ago 2026 | Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the… |
| CVE-2026-17601 | Alta (8.9) | 0.29% | — | 7 ago 2026 | A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full… |
| CVE-2026-17600 | Alta (8.7) | 0.25% | — | 7 ago 2026 | Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose… |
| CVE-2026-17599 | Media (6.9) | 0.34% | — | 7 ago 2026 | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password… |
| CVE-2026-17598 | Media (5.3) | 0.23% | — | 7 ago 2026 | Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission… |
| CVE-2026-17597 | Media (5.1) | 0.23% | — | 7 ago 2026 | Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port… |
| CVE-2026-17596 | Media (6.3) | 0.24% | — | 7 ago 2026 | Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script… |
| CVE-2026-17595 | Media (5.3) | 0.23% | — | 7 ago 2026 | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended… |
| CVE-2026-17594 | Alta (8.2) | 0.74% | — | 7 ago 2026 | Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated… |
| CVE-2026-17593 | Alta (7.2) | 0.77% | — | 7 ago 2026 | An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an… |
| CVE-2026-14644 | Alta (8.6) | 0.34% | — | 7 ago 2026 | Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own… |
| CVE-2026-14646 | Media (4.9) | 0.26% | — | 14 jul 2026 | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed… |
| CVE-2026-14645 | Media (5.1) | 0.26% | — | 14 jul 2026 | Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause… |
| CVE-2026-7494 | Media (5.3) | 0.17% | — | 14 jul 2026 | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound… |
| CVE-2026-14504 | Alta (8.2) | 0.22% | — | 14 jul 2026 | An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the… |
| CVE-2026-11403 | Alta (8.7) | 0.32% | — | 14 jul 2026 | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key… |
| CVE-2026-10741 | Media (5.9) | 0.27% | — | 17 jun 2026 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy… |
| CVE-2026-10748 | Alta (8.6) | 0.32% | — | 16 jun 2026 | An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions… |
| CVE-2026-3329 | Alta (8.7) | 0.63% | — | 11 jun 2026 | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. |
| CVE-2026-7308 | Media (5.1) | 0.40% | — | 11 may 2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page… |
| CVE-2026-3048 | Media (5.1) | 0.29% | — | 11 may 2026 | An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting… |
| CVE-2026-5189 | Crítica (9.2) | 0.62% | — | 15 abr 2026 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal… |
| CVE-2026-3438 | Media (5.1) | 0.61% | — | 8 abr 2026 | A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through… |
| CVE-2026-3199 | Crítica (9.4) | 0.77% | — | 8 abr 2026 | A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the… |
| CVE-2024-5764 | Media (5.9) | 0.39% | — | 23 oct 2024 | Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.