CVE-2014-2034: Sonatype Nexus
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
Affected products
- Sonatype Nexus: version 2.4.0 only; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; …
Published 2014-04-01. Last modified 2026-06-17.