First published: Thu Aug 22 2019(Updated: )
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sonatype Nexus Repository Manager | >=3.14.0<=3.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14469 is a vulnerability in Nexus Repository Manager before version 3.18.0 where users with elevated privileges can create stored XSS (Cross-Site Scripting) attacks.
Users of Nexus Repository Manager versions between 3.14.0 and 3.17.0 with elevated privileges can be affected by CVE-2019-14469.
The severity of CVE-2019-14469 is considered medium with a CVSS score of 5.4.
To fix CVE-2019-14469, users should upgrade to Nexus Repository Manager version 3.18.0 or later.
More information about CVE-2019-14469 can be found on the Sonatype support website at https://support.sonatype.com/hc/en-us/articles/360033999733-CVE-2019-14469-Nexus-Repository-Manager-3-Cross-Site-Scripting-XSS-2019-07-26.