Sonatype Nexus Repository Manager Vulnerability Advisories (Severity Critical and Medium)

A remote code execution vulnerability CVE-2020-15871 of critical severity has been discovered in Nexus Repository Manager 3. We have fixed the vulnerability in version 3.25.1 The vulnerability was discovered and reported by nike.zheng@dbappsecurity.com.cn from Dbappsecurity Co., Ltd. See Sonatype’s KB article for more detail: https://support.sonatype.com/hc/en-us/articles/360052192693

A XSS vulnerability CVE-2020-15869 of medium severity has been discovered in Nexus Repository Manager 3. We have fixed the vulnerability in version 3.25.1 The vulnerability was discovered and reported by nike.zheng@dbappsecurity.com.cn from Dbappsecurity Co., Ltd. See Sonatype’s KB article for more detail: https://support.sonatype.com/hc/en-us/articles/360051424554

A XSS vulnerability CVE-2020-15870 of medium severity has been discovered in Nexus Repository Manager 3. We have fixed the vulnerability in version 3.25.1 The vulnerability was discovered and reported by nike.zheng@dbappsecurity.com.cn from Dbappsecurity Co., Ltd.
See Sonatype’s KB article for more detail: https://support.sonatype.com/hc/en-us/articles/360051424754