CVE-2019-5475: Sonatype Nexus Repository Manager
High severity, CVSS 8.8. EPSS: 18.4% chance of exploitation in the next 30 days.
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Affected products
- Sonatype Nexus Repository Manager: from 2.0, up to and including 2.14.9-01
Published 2019-09-03. Last modified 2026-06-17.