OS Command Injection in Nexus Yum Repository Plugin
High severity
GitHub Reviewed
Published
Sep 11, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
< 2.14.14
Patched versions
2.14.14
Description
Published by the National Vulnerability Database
Sep 3, 2019
Reviewed
Sep 4, 2019
Published to the GitHub Advisory Database
Sep 11, 2019
Last updated
Feb 1, 2023
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
References