CVE-2014-0792

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sonatype:nexus:1.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.4:1:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:04:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:05:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:06:*:*:*:*:*:*

History

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://www.sonatype.org/advisories/archive/2014-01-13-Nexus - Patch, Vendor Advisory () http://www.sonatype.org/advisories/archive/2014-01-13-Nexus - Patch, Vendor Advisory
References () https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist - () https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist -
References () https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability - Patch, Vendor Advisory () https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability - Patch, Vendor Advisory

Information

Published : 2014-01-17 20:55

Updated : 2024-11-21 02:02


NVD link : CVE-2014-0792

Mitre link : CVE-2014-0792

CVE.ORG link : CVE-2014-0792


JSON object : View

Products Affected

sonatype

  • nexus
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')