Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2022-25842 Vulnerability in maven package com.alibaba.oneagent:one-java-agent-plugin
CVE-2023-38493 Vulnerability in maven package com.linecorp.armeria:armeria
CVE-2023-2512 Vulnerability in npm package workerd
CVE-2023-33940 Vulnerability in maven package com.liferay:com.liferay.client.extension.type.impl
CVE-2021-46364 Vulnerability in maven package info.magnolia:magnolia-core