Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
References
Link | Resource |
---|---|
https://support.sonatype.com | Vendor Advisory |
https://support.sonatype.com/hc/en-us/articles/4404115639827 | Vendor Advisory |
Configurations
History
16 Aug 2021, 18:17
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:* | |
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
References | (MISC) https://support.sonatype.com - Vendor Advisory | |
References | (MISC) https://support.sonatype.com/hc/en-us/articles/4404115639827 - Vendor Advisory |
10 Aug 2021, 15:07
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-10 14:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-37152
Mitre link : CVE-2021-37152
CVE.ORG link : CVE-2021-37152
JSON object : View
Products Affected
sonatype
- nexus_repository_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')