CVE-2020-15012
HIGHSonatype Nexus Repository Manager <2.14.19 - Path Traversal
Title source: llmDescription
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://support.sonatype.com/hc/en-us/articles/360051068253
Scores
CVSS v3
8.6
EPSS
0.0256
EPSS Percentile
83.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
sonatype/nexus_repository_manager
2.0 - 2.14.19
Published
Oct 12, 2020
Tracked Since
Feb 18, 2026