Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sonatype Nexus 代码注入漏洞
Vulnerability Description
Sonatype Nexus是美国Sonatype公司的一款可通过一小段描述信息来管理项目的构建、报告和文档的项目管理工具(仓库管理器)。该工具能够实现代理远程仓库、创建本地宿主仓库及仓库组等。 Sonatype Nexus 1.x和2.7.1之前的2.x版本中存在代码注入漏洞。远程攻击者可利用该漏洞创建任意对象,并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A