org.sonatype.nexus:nexus-repository@3.30.1-01

  • latest version

    3.70.1-02

  • first published

    11 years ago

  • latest version published

    2 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.sonatype.nexus:nexus-repository package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the HTML index page when an authenticated user with upload permissions stores crafted content. An attacker can execute arbitrary JavaScript in the browser of users who browse the affected repository directory, potentially performing actions in the context of the victim's session.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.92.0 or higher.

    [3.6.0,3.92.0)
    • M
    Server-side Request Forgery (SSRF)

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the LDAP connectivity configuration component. An attacker can cause the server to initiate unintended outbound connections by supplying a malicious LDAP server during configuration or testing. This is only exploitable if an authenticated administrator interacts with a malicious LDAP server during LDAP connectivity setup or testing.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.92.0 or higher.

    [3.0.0,3.92.0)
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the ?describe page when user-supplied input is reflected in the response without proper sanitization. An attacker can execute JavaScript in the context of a victim's browser by convincing the user to click a malicious URL.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.91.0 or higher.

    [,3.91.0)
    • C
    Deserialization of Untrusted Data

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data involving task management that allows authenticated users with task creation permissions to execute arbitrary code by injecting malicious properties into a serialized object. A user can bypass nexus.scripts.allowCreation restrictions that should prevent code execution.

    How to fix Deserialization of Untrusted Data?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.91.0 or higher.

    [3.22.1,3.91.0)
    • H
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal. An attacker can craft a URL to return any file as a download, including system files outside of Nexus Repository application scope, without any authentication.

    How to fix Directory Traversal?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.68.1 or higher.

    [,3.68.1)
    • M
    Server-side Request Forgery (SSRF)

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF). A remote authenticated attacker can potentially perform network enumeration.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.36.0 or higher.

    [,3.36.0)
    • C
    HTTP Header Injection

    Affected versions of this package are vulnerable to HTTP Header Injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

    How to fix HTTP Header Injection?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.34.0-01 or higher.

    [,3.34.0-01)
    • M
    Information Exposure

    Affected versions of this package are vulnerable to Information Exposure. A remote authenticated attacker is able to get a list of blob files and read the content of a blob file via a GET request without having been granted access.

    How to fix Information Exposure?

    Upgrade org.sonatype.nexus:nexus-repository to version 3.31.0-01 or higher.

    [,3.31.0-01)