Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2021-21179 Vulnerability in npm package electron
CVE-2023-49380 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-23223 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:github-com-faisalman-ua-parser-js
CVE-2023-43497 Vulnerability in maven package org.jenkins-ci.main:jenkins-core