CVE-2014-0792

S

onatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sonatype:nexus:1.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.4:1:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:04:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:05:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus:2.7.0:06:*:*:*:*:*:*

History

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://www.sonatype.org/advisories/archive/2014-01-13-Nexus - Patch, Vendor Advisory () http://www.sonatype.org/advisories/archive/2014-01-13-Nexus - Patch, Vendor Advisory
References () https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist - () https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist -
References () https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability - Patch, Vendor Advisory () https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability - Patch, Vendor Advisory

Information

Published : 2014-01-17 20:55

Updated : 2025-04-11 00:51


NVD link : CVE-2014-0792

Mitre link : CVE-2014-0792

CVE.ORG link : CVE-2014-0792


JSON object : View

Products Affected
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')