FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-28 15:43:32 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
b2f9573a-008c-11ea-9801-10c37b4ac2eanexus2-oss -- Multiple vulerabilities

Sonatype reports:

Several RCE vulnerabilities have been found and corrected in 2.14.15:

CVE-2019-16530: An attacker with elevated privileges can upload a specially crafted file. That file can contain commands that will be executed on the system, with the same privileges as the user running the server.

CVE-2019-15893: A Remote Code Execution vulnerability has been discovered in Nexus Repository Manager requiring immediate action. The vulnerability allows for an attacker with administrative access to NXRM to create repostories that can grant access to read/execute system data outside the scope of NXRM.

CVE-2019-5475: A vulnerability has been found that can allow user's with administrative privileges to run processes on the target server, that the nxrm os user has access to.


Discovery 2019-09-19
Entry 2019-11-07
nexus2-oss
< 2.14.15

CVE-2019-16530
CVE-2019-15893
CVE-2019-5475
b2f1f86f-20e6-11ec-a574-080027eedc6anexus2-oss -- NXRM2 Directory Traversal vulnerability

Sonatype reports:

  • CVE-2020-15012: NXRM2 Directory Traversal vulnerability

Discovery 2020-06-23
Entry 2021-09-29
nexus2-oss
< 2.14.19

CVE-2020-15012
https://help.sonatype.com/repomanager2/release-notes/2020-release-notes#id-2020ReleaseNotes-RepositoryManage
730e922f-20e7-11ec-a574-080027eedc6anexus2-oss -- Apache ActiveMQ JMX vulnerability

Sonatype reports:

  • CVE-2020-13920: Apache ActiveMQ JMX is vulnerable to a MITM attack

Discovery 2020-12-28
Entry 2021-09-29
nexus2-oss
< 2.14.20

CVE-2020-13920
https://help.sonatype.com/repomanager2/release-notes/2020-release-notes#id-2020ReleaseNotes-RepositoryManage