The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g5m7-57ph-j6p8 OS Command Injection in Nexus Yum Repository Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-04T19:54:53.577Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5475

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-03T20:15:11.467

Modified: 2024-11-21T04:45:00.383

Link: CVE-2019-5475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.