CVE-2020-15870: XSS
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15870?
CVE-2020-15870 is a vulnerability in Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 that allows XSS (Cross-Site Scripting) attacks.
What is Sonatype Nexus Repository Manager?
Sonatype Nexus Repository Manager is a software product that allows users to store and distribute software components in a central repository.
How does CVE-2020-15870 impact Sonatype Nexus Repository Manager?
CVE-2020-15870 allows attackers to perform XSS (Cross-Site Scripting) attacks on Sonatype Nexus Repository Manager, potentially leading to the execution of malicious scripts on the user's browser.
What is the severity of CVE-2020-15870?
The severity of CVE-2020-15870 is medium, with a CVSS (Common Vulnerability Scoring System) score of 6.1.
How can I fix CVE-2020-15870?
To fix CVE-2020-15870, users should upgrade to Sonatype Nexus Repository Manager OSS/Pro version 3.25.1 or later.