« Volver al listado

Sonatype

Sonatype Nexus Repository Manager: vulnerabilidades y CVE

Sonatype Nexus Repository Manager tiene 64 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE64
Últimos 12 meses29
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-7238Crítica (9.8)77%⚠ Explotación activa21 mar 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77125Alta (7.1)0.29%—2 sept 2026
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the…
CVE-2026-77124Alta (7.5)0.72%—2 sept 2026
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding…
CVE-2026-77123Media (6)0.46%—2 sept 2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a…
CVE-2026-77122Media (5.3)0.28%—2 sept 2026
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group…
CVE-2026-77121Media (5.3)0.25%—2 sept 2026
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components…
CVE-2026-17603Alta (8.7)0.48%—7 ago 2026
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the…
CVE-2026-17601Alta (8.9)0.29%—7 ago 2026
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full…
CVE-2026-17600Alta (8.7)0.25%—7 ago 2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose…
CVE-2026-17599Media (6.9)0.34%—7 ago 2026
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password…
CVE-2026-17598Media (5.3)0.23%—7 ago 2026
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission…
CVE-2026-17597Media (5.1)0.23%—7 ago 2026
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port…
CVE-2026-17596Media (6.3)0.24%—7 ago 2026
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script…
CVE-2026-17595Media (5.3)0.23%—7 ago 2026
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended…
CVE-2026-17594Alta (8.2)0.74%—7 ago 2026
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated…
CVE-2026-17593Alta (7.2)0.77%—7 ago 2026
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an…
CVE-2026-14644Alta (8.6)0.34%—7 ago 2026
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own…
CVE-2026-14646Media (4.9)0.26%—14 jul 2026
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed…
CVE-2026-14645Media (5.1)0.26%—14 jul 2026
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause…
CVE-2026-7494Media (5.3)0.17%—14 jul 2026
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound…
CVE-2026-14504Alta (8.2)0.22%—14 jul 2026
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the…
CVE-2026-11403Alta (8.7)0.32%—14 jul 2026
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key…
CVE-2026-10741Media (5.9)0.27%—17 jun 2026
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy…
CVE-2026-10748Alta (8.6)0.32%—16 jun 2026
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions…
CVE-2026-3329Alta (8.7)0.63%—11 jun 2026
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
CVE-2026-7308Media (5.1)0.40%—11 may 2026
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page…
CVE-2026-3048Media (5.1)0.29%—11 may 2026
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting…
CVE-2026-5189Crítica (9.2)0.62%—15 abr 2026
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal…
CVE-2026-3438Media (5.1)0.61%—8 abr 2026
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through…
CVE-2026-3199Crítica (9.4)0.77%—8 abr 2026
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the…
CVE-2024-5764Media (5.9)0.39%—23 oct 2024
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services10
  2. T1059 Command and Scripting Interpreter6
  3. T1190 Exploit Public-Facing Application5
  4. T1078 Valid Accounts4
  5. T1078.001 Default Accounts4
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Sonatype