CVE-2014-0792: Sonatype Nexus

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.

Affected products

  • Sonatype Nexus: version 1.0 only; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2014-01-17. Last modified 2026-06-17.