CVE-2020-15871: High severity Sonatype Nexus Repository Manager 3 vulnerability
Published Jul 31, 2020
·Updated
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
Affected Software
3 affected components
Sonatype Nexus Repository Manager 3<3.25.1
Sonatype Nexus Repository Manager 3<3.25.1
Sonatype Nexus Repository Manager<3.25.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sonatype Nexus Repository Manager OSS/Proto a version that resolves this vulnerability.Fixed in 3.25.1
Event History
Jul 31, 2020
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-15871.
2
What is the severity level of CVE-2020-15871?
The severity level of CVE-2020-15871 is high (8.8).
3
What is the affected software for CVE-2020-15871?
The affected software for CVE-2020-15871 is Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1.
4
How does CVE-2020-15871 allow Remote Code Execution?
CVE-2020-15871 allows Remote Code Execution in Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1.
5
How can I fix CVE-2020-15871?
To fix CVE-2020-15871, you should update your Sonatype Nexus Repository Manager OSS/Pro to version 3.25.1 or higher.