PT-2019-14688 · Sonatype · Sonatype Iq Server+2

Publicado

2019-10-21

·

Atualizado

2022-05-24

·

CVE-2019-16530

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository Manager versions 2.x through 2.14.14 Sonatype Nexus Repository Manager versions 3.x through 3.18 Sonatype IQ Server versions prior to 72
Description The issue allows for remote code execution.
Recommendations For Sonatype Nexus Repository Manager versions 2.x through 2.14.14, update to version 2.14.15 or later. For Sonatype Nexus Repository Manager versions 3.x through 3.18, update to version 3.19 or later. For Sonatype IQ Server versions prior to 72, update to version 72 or later.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16530
GHSA-HMJV-PX3J-933C

Produtos afetados

Nexus Repository Manager
Sonatype Iq Server
Sonatype Nexus Repository Manager