Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2020-26296 Vulnerability in maven package org.webjars.bowergithub.vega:vega
CVE-2020-7650 Vulnerability in npm package snyk-broker
CVE-2013-4221 Vulnerability in maven package org.restlet:org.restlet
CVE-2020-16017 Vulnerability in npm package electron
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions