Skip to main content
Sonatype Peter Sandbox Help Center home page My Sonatype
Community
Forum Ideas Office Hours Innovate
Learn
Courses Videos
Support
Knowledge Base Documentation
Resources
SSC Maturity Survey STEPP Assessment Hosted Workshops
Sign In Submit a request Sign In

Forum Ideas Office Hours Innovate
Courses Videos
Knowledge Base Documentation
SSC Maturity Survey STEPP Assessment Hosted Workshops
  1. Sonatype Peter Sandbox
  2. Announcements
  3. Security Advisories

Security Advisories

Important advisories of known security vulnerabilities in Sonatype products.

  • CVE-2020-10199 Nexus Repository 3 - Remote Code Execution - 2020-03-31
  • CVE-2019-16530 Nexus Repository 2 & 3, and IQ Server - Remote Code Execution - 2019-09-19
  • CVE-2019-15893 Nexus Repository 2 - Remote Code Execution - 2019-09-03
  • CVE-2019-5475 & sonatype-2019-0429 (CVE-2019-15588) Nexus Repository 2 - OS Command Injection - 2019-08-09
  • CVE-2019-14469 Nexus Repository 3 - Cross Site Scripting XSS - 2019-07-26
  • CVE-2019-11629 Nexus Repository 2 - Cross Site Scripting XSS - 2019-05-02
  • CVE-2019-7238 Nexus Repository 3 - Missing Access Controls and Remote Code Execution - 2019-02-05
  • CVE-2018-16619 Nexus Repository Manager 3 - Cross Site Scripting XSS - 2018-10-17
  • CVE-2018-16620 Nexus Repository 3 - Missing Access Controls - 2018-10-17
  • CVE-2018-16621 Nexus Repository 3 - Java Injection - 2018-10-17
  • CVE-2018-12100 Nexus Repository 3 - Cross-Site Scripting XSS - 2018-06-04
  • CVE-2018-5307 Nexus Repository 2 - Cross-Site Scripting XSS - 2018-02-08
  • CVE-2018-5306 Nexus Repository 3 - Cross-Site Scripting XSS - 2018-02-08
  • CVE-2016-4437 Nexus Repository 2 - Remote Code Execution - 2016-06-20
  • CVE-2014-9389 Nexus Repository 2 - Directory Traversal - 2014-12-23
  • CVE-2014-2034 Nexus Repository 2 - REST API Account Creation - 2014-03-03
  • CVE-2014-0792 Nexus Repository 2 - xstream Remote Code Execution - 2014-01-09
  • « First
  • ‹ Previous
Terms of Service Privacy Policy Cookie Preferences
Copyright © 2008-present, Sonatype Inc. All rights reserved. Includes the third-party code listed here. Sonatype and Sonatype Nexus are trademarks of Sonatype, Inc. Apache Maven and Maven are trademarks of the Apache Software Foundation. M2Eclipse is a trademark of the Eclipse Foundation. All other trademarks are the property of their respective owners.