GHSL-2020-015: Remote Code Execution - Bypass of CVE-2018-16621 mitigations in Nexus Repository Manager
Published Apr 13, 2020
·Updated
GHSL-2020-015 - Remote Code Execution - Bypass of CVE-2018-16621 mitigations
Affected Software
1 affected component
Sonatype Nexus Repository Manager
Event History
Apr 13, 2020
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2020-015?
GHSL-2020-015 has a high severity rating of 89, indicating a critical risk level.
2
What is the impact of the vulnerability GHSL-2020-015?
GHSL-2020-015 allows for remote code execution by bypassing previous mitigations of CVE-2018-16621 within the Nexus Repository Manager.
3
How do I fix GHSL-2020-015?
To mitigate GHSL-2020-015, ensure that you upgrade to the latest patched version of Sonatype Nexus Repository Manager as per the vendor's guidance.
4
Which software is affected by GHSL-2020-015?
GHSL-2020-015 affects Sonatype Nexus Repository Manager.
5
When was GHSL-2020-015 published?
GHSL-2020-015 was published on April 13, 2020.