Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2023-40315 Vulnerability in maven package org.opennms:opennms-webapp-rest
CVE-2020-24616 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-5413 Vulnerability in maven package org.springframework.integration:spring-integration
CVE-2023-50710 Vulnerability in npm package hono
CVE-2023-26136 Vulnerability in maven package org.webjars.bowergithub.salesforce:tough-cookie