Vulnerabilidades en Sonatype

33 resultados
Análisis Vexday

Sonatype apresenta 22 vulnerabilidades conhecidas com 2 classificadas como críticas, sendo 10 publicadas nos últimos 90 dias — indicativo de atividade recente na superfície de ataque. Nenhuma vulnerabilidade está sob exploração ativa conhecida (KEV zero), reduzindo a pressão operacional imediata. A fraqueza dominante é CWE-918 (Server-Side Request Forgery), típica em ferramentas de análise e gestão de dependências, requerendo atenção em ambientes com acesso a redes internas.

CVE-2024-4956HIGHNexus Repository 3 - Path TraversalEPSS 18.2%CVE-2024-5082HIGHNexus Repository 2 - Remote Code ExecutionEPSS 2.0%CVE-2024-1142MEDIUMSonatype IQ Server - Path TraversalEPSS 0.7%CVE-2026-3199CRITICALNexus Repository 3 - Authenticated Remote Code Execution via Task Property InjectionEPSS 0.5%CVE-2026-3438MEDIUMNexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe PagesEPSS 0.5%CVE-2025-9868HIGHNexus Repository 2 - SSRF Vulnerability in Remote Browser PluginEPSS 0.5%CVE-2026-5189CRITICALNexus Repository 3 - Hardcoded Credential in Internal Database ComponentEPSS 0.5%CVE-2026-3329HIGHNexus Repository Manager - Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2024-5083MEDIUMNexus Repository 2 - Stored XSSEPSS 0.4%CVE-2026-14645MEDIUMNexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global CapabilityEPSS 0.4%CVE-2024-5764MEDIUMNexus Repository 3 - Static hard-coded encryption passphrase used by defaultEPSS 0.4%CVE-2026-0601MEDIUMNexus Repository 3 - Cross-Site ScriptingEPSS 0.4%CVE-2026-17603HIGHNexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration APIEPSS 0.4%CVE-2026-11403HIGHNexus Repository Manager - Insufficient Entropy in Format-Specific API Key GenerationEPSS 0.3%CVE-2025-13488MEDIUMNexus Repository 3 - Stored Cross-Site Scripting (XSS)EPSS 0.3%CVE-2026-17593HIGHNexus Repository - Arbitrary Class Instantiation via Unsafe Realm ConfigurationEPSS 0.3%CVE-2026-10748HIGHNexus Repository 3 - Remote Code Execution via License DeserializationEPSS 0.3%CVE-2026-17599MEDIUMNexus Repository 3 - Unverified Onboarding State on change-admin-password EndpointEPSS 0.3%CVE-2026-17597MEDIUMNexus Repository 3 - Server-Side Request Forgery via Email Configuration VerificationEPSS 0.3%CVE-2026-17595MEDIUMNexus Repository 3 - JEXL Content Selector Sandbox Property-Read BypassEPSS 0.3%