Nexus Repository Manager Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2019-5475 - Vulnerability Database
Nexus Repository Manager Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2019-5475
High
Reference:
CVE-2019-5475
Title:
Nexus Repository Manager Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability
Overview:
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data such as the Yum Configuration Capability.