ZeroHour

CVE-2019-5475

PoC
CVSS 3.0
8.8 high
EPSS
18%p97
Published
()
Modified
Description

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

Vendors
sonatype
Products
nexus repository manager
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.