Stored Cross-Site Scripting Vulnerability in Nexus Repository Manager by Sonatype
CVE-2019-14469

5.4MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
22 August 2019

What is CVE-2019-14469?

A stored cross-site scripting vulnerability exists in Nexus Repository Manager prior to version 3.18.0. This flaw allows users with elevated privileges to create malicious scripts that are stored and executed in the context of other users' sessions, potentially leading to unauthorized actions and data exposure. Organizations using affected versions should apply the latest updates to mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.