Description
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/360036132453
Related Vulnerabilities
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2023-41329 Vulnerability in maven package com.github.tomakehurst:wiremock-jre8-standalone
CVE-2021-23444 Vulnerability in npm package jointjs
CVE-2023-41327 Vulnerability in maven package org.wiremock:wiremock-webhooks-extension