Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2023-26136 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2022-22984 Vulnerability in npm package snyk-mvn-plugin
CVE-2022-34813 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin
CVE-2018-25007 Vulnerability in maven package com.vaadin:flow-server