CVE-2020-15012: Sonatype Nexus Repository Manager
High severity, CVSS 8.6. EPSS: 2.6% chance of exploitation in the next 30 days.
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).
Affected products
- Sonatype Nexus Repository Manager: from 2.0, before 2.14.19 (fixed in 2.14.19)
Published 2020-10-12. Last modified 2026-06-17.