sonatype CVE Vulnerabilities & Metrics

Focus on sonatype vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About sonatype Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sonatype. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sonatype CVEs: 41
Earliest CVE date: 17 Jan 2014, 20:55 UTC
Latest CVE date: 23 Oct 2024, 15:15 UTC

Latest CVE reference: CVE-2024-5764

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sonatype CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.61

Max CVSS: 10.0

Critical CVEs (≥9): 6

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 26
7.0-8.9 6
9.0-10.0 6

CVSS Distribution Chart

Top 5 Highest CVSS sonatype CVEs

These are the five CVEs with the highest CVSS scores for sonatype, sorted by severity first and recency.

All CVEs for sonatype

CVE-2024-5764 sonatype vulnerability CVSS: 0 23 Oct 2024, 15:15 UTC

Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated. This issue affects Nexus Repository: from 3.0.0 through 3.72.0.

CVE-2022-27907 sonatype vulnerability CVSS: 4.0 30 Mar 2022, 16:15 UTC

Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

CVE-2021-43961 sonatype vulnerability CVSS: 4.3 17 Mar 2022, 22:15 UTC

Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.

CVE-2021-43293 sonatype vulnerability CVSS: 4.0 04 Nov 2021, 18:15 UTC

Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

CVE-2021-42568 sonatype vulnerability CVSS: 4.0 02 Nov 2021, 13:15 UTC

Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.

CVE-2021-40143 sonatype vulnerability CVSS: 6.4 07 Sep 2021, 20:15 UTC

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

CVE-2021-37152 sonatype vulnerability CVSS: 3.5 10 Aug 2021, 14:15 UTC

Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.

CVE-2021-34553 sonatype vulnerability CVSS: 4.0 18 Jun 2021, 00:15 UTC

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

CVE-2021-29159 sonatype vulnerability CVSS: 4.3 28 Apr 2021, 14:15 UTC

A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.

CVE-2021-30635 sonatype vulnerability CVSS: 5.0 27 Apr 2021, 03:15 UTC

Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).

CVE-2021-29158 sonatype vulnerability CVSS: 4.0 23 Apr 2021, 21:15 UTC

Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

CVE-2020-29436 sonatype vulnerability CVSS: 5.5 17 Dec 2020, 02:15 UTC

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.

CVE-2020-15012 sonatype vulnerability CVSS: 7.8 12 Oct 2020, 21:15 UTC

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).

CVE-2020-24622 sonatype vulnerability CVSS: 4.0 25 Aug 2020, 19:15 UTC

In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

CVE-2020-15868 sonatype vulnerability CVSS: 5.0 12 Aug 2020, 22:15 UTC

Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.

CVE-2020-15871 sonatype vulnerability CVSS: 6.8 31 Jul 2020, 20:15 UTC

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

CVE-2020-15870 sonatype vulnerability CVSS: 4.3 31 Jul 2020, 20:15 UTC

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).

CVE-2020-15869 sonatype vulnerability CVSS: 4.3 31 Jul 2020, 20:15 UTC

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

CVE-2020-11415 sonatype vulnerability CVSS: 4.0 27 Apr 2020, 15:15 UTC

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

CVE-2020-11753 sonatype vulnerability CVSS: 6.5 20 Apr 2020, 19:15 UTC

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).

CVE-2020-11444 sonatype vulnerability CVSS: 6.5 02 Apr 2020, 18:15 UTC

Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

CVE-2020-10204 sonatype vulnerability CVSS: 9.0 01 Apr 2020, 19:15 UTC

Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

CVE-2020-10203 sonatype vulnerability CVSS: 3.5 01 Apr 2020, 19:15 UTC

Sonatype Nexus Repository before 3.21.2 allows XSS.

CVE-2020-10199 sonatype vulnerability CVSS: 9.0 01 Apr 2020, 19:15 UTC

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

CVE-2019-15588 sonatype vulnerability CVSS: 9.0 01 Nov 2019, 15:15 UTC

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.

CVE-2019-16530 sonatype vulnerability CVSS: 9.0 21 Oct 2019, 14:15 UTC

Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

CVE-2019-15893 sonatype vulnerability CVSS: 6.5 16 Oct 2019, 14:15 UTC

Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.

CVE-2019-5475 sonatype vulnerability CVSS: 9.0 03 Sep 2019, 20:15 UTC

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

CVE-2019-14469 sonatype vulnerability CVSS: 3.5 22 Aug 2019, 18:15 UTC

In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.

CVE-2019-9630 sonatype vulnerability CVSS: 5.0 08 Jul 2019, 19:15 UTC

Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.

CVE-2019-9629 sonatype vulnerability CVSS: 7.5 08 Jul 2019, 19:15 UTC

Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

CVE-2019-11629 sonatype vulnerability CVSS: 4.3 07 May 2019, 18:29 UTC

Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.

CVE-2019-7238 sonatype vulnerability CVSS: 7.5 21 Mar 2019, 17:29 UTC

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

CVE-2018-16621 sonatype vulnerability CVSS: 6.5 15 Nov 2018, 20:29 UTC

Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

CVE-2018-16620 sonatype vulnerability CVSS: 5.0 15 Nov 2018, 20:29 UTC

Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.

CVE-2018-16619 sonatype vulnerability CVSS: 4.3 15 Nov 2018, 20:29 UTC

Sonatype Nexus Repository Manager before 3.14 allows XSS.

CVE-2018-12100 sonatype vulnerability CVSS: 3.5 11 Jun 2018, 11:29 UTC

Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.

CVE-2018-5307 sonatype vulnerability CVSS: 4.3 09 Feb 2018, 22:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.

CVE-2018-5306 sonatype vulnerability CVSS: 4.3 09 Feb 2018, 22:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.

CVE-2017-17717 sonatype vulnerability CVSS: 10.0 17 Dec 2017, 17:29 UTC

Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

CVE-2014-9389 sonatype vulnerability CVSS: 7.5 05 Jan 2015, 20:59 UTC

Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.

CVE-2014-2034 sonatype vulnerability CVSS: 7.5 01 Apr 2014, 03:25 UTC

Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."

CVE-2014-0792 sonatype vulnerability CVSS: 7.5 17 Jan 2014, 20:55 UTC

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.