CVE-2014-2034

Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sonatype:nexus:2.4.0:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.4.0:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.0:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.0:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.0:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.0:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.1:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.1:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.2:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.2:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.3:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.3:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.4:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.4:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.5:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:*:*:*:professional:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.1:*:*:*:open_source:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.1:*:*:*:professional:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://secunia.com/advisories/57142 - Vendor Advisory () http://secunia.com/advisories/57142 - Vendor Advisory
References () http://www.osvdb.org/104049 - () http://www.osvdb.org/104049 -
References () http://www.securityfocus.com/bid/65956 - () http://www.securityfocus.com/bid/65956 -
References () http://www.sonatype.org/advisories/archive/2014-03-03-Nexus - Vendor Advisory () http://www.sonatype.org/advisories/archive/2014-03-03-Nexus - Vendor Advisory
References () https://support.sonatype.com/entries/42374566-CVE-2014-2034-Nexus-Security-Advisory-REST-API - Vendor Advisory () https://support.sonatype.com/entries/42374566-CVE-2014-2034-Nexus-Security-Advisory-REST-API - Vendor Advisory

Information

Published : 2014-04-01 03:25

Updated : 2024-11-21 02:05


NVD link : CVE-2014-2034

Mitre link : CVE-2014-2034

CVE.ORG link : CVE-2014-2034


JSON object : View

Products Affected

sonatype

  • nexus