Description
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP REST API (WP API) Information Disclosure (1.2)
WordPress 'blog.header.php' Multiple SQL Injection Vulnerabilities (0.6.2 - 0.71)
Atlassian Jira Observable Discrepancy Vulnerability (CVE-2020-4028)
WordPress Plugin Defa Online Image Protector Cross-Site Scripting (3.3)
Oracle HTTP Server Uncontrolled Search Path Element Vulnerability (CVE-2019-5443)