CVE-2020-15012: Sonatype Nexus Repository Manager

High severity, CVSS 8.6. EPSS: 2.6% chance of exploitation in the next 30 days.

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).

Affected products

  • Sonatype Nexus Repository Manager: from 2.0, before 2.14.19 (fixed in 2.14.19)

Published 2020-10-12. Last modified 2026-06-17.