Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2021-36373 Vulnerability in maven package org.apache.ant:ant
CVE-2019-11343 Vulnerability in maven package org.torpedoquery:org.torpedoquery
CVE-2023-36472 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2023-34466 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-api
CVE-2021-21193 Vulnerability in maven package org.webjars.npm:electron