Unrated severityNVD Advisory· Published Apr 28, 2021· Updated Aug 3, 2024
CVE-2021-29159
CVE-2021-29159
Description
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
Affected products
2- Nexus Repository/Nexus Repository Managerdescription
- Range: <3.30.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.sonatype.com/hc/en-us/articles/1500005031082mitrex_refsource_MISC
- support.sonatype.com/hc/en-us/categories/201980768-Welcome-to-the-Sonatype-Support-Knowledge-Basemitrex_refsource_MISC
News mentions
0No linked articles in our index yet.