First published: Tue May 07 2019(Updated: )
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonatype Nexus Repository Manager | >=2.0.0<2.14.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11629 is a vulnerability in Sonatype Nexus Repository Manager 2.x before version 2.14.13 that allows for cross-site scripting (XSS) attacks.
The severity of CVE-2019-11629 is ranked as medium with a CVSS score of 6.1.
CVE-2019-11629 affects Sonatype Nexus Repository Manager 2.x before version 2.14.13, allowing for cross-site scripting (XSS) attacks.
You can find more information about CVE-2019-11629 in the Sonatype support article at https://support.sonatype.com/hc/en-us/articles/360022528733-CVE-2019-11629-Nexus-Repository-Manager-2-Cross-Site-Scripting-XSS-2019-05-02.
The CWE category for CVE-2019-11629 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation.