FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

nexus2-oss -- Multiple vulerabilities

Affected packages
nexus2-oss < 2.14.15

Details

VuXML ID b2f9573a-008c-11ea-9801-10c37b4ac2ea
Discovery 2019-09-19
Entry 2019-11-07

Sonatype reports:

Several RCE vulnerabilities have been found and corrected in 2.14.15:

CVE-2019-16530: An attacker with elevated privileges can upload a specially crafted file. That file can contain commands that will be executed on the system, with the same privileges as the user running the server.

CVE-2019-15893: A Remote Code Execution vulnerability has been discovered in Nexus Repository Manager requiring immediate action. The vulnerability allows for an attacker with administrative access to NXRM to create repostories that can grant access to read/execute system data outside the scope of NXRM.

CVE-2019-5475: A vulnerability has been found that can allow user's with administrative privileges to run processes on the target server, that the nxrm os user has access to.

References

CVE Name CVE-2019-15893
CVE Name CVE-2019-16530
CVE Name CVE-2019-5475