{"id":"GHSA-hmjv-px3j-933c","summary":"Unrestricted Upload of File with Dangerous Type in Sonatype Nexus Repository Manager","details":"Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.","aliases":["CVE-2019-16530"],"modified":"2023-11-08T04:01:17.983202Z","published":"2022-05-24T16:59:30Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-27T21:31:46Z","nvd_published_at":"2019-10-21T14:15:00Z","cwe_ids":["CWE-434"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16530"},{"type":"WEB","url":"https://issues.sonatype.org/secure/ReleaseNote.jspa"},{"type":"WEB","url":"https://support.sonatype.com/hc/en-us/articles/360036132453"}],"affected":[{"package":{"name":"org.sonatype.nexus:nexus-repository","ecosystem":"Maven","purl":"pkg:maven/org.sonatype.nexus/nexus-repository"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.14.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hmjv-px3j-933c/GHSA-hmjv-px3j-933c.json"}},{"package":{"name":"org.sonatype.nexus:nexus-repository","ecosystem":"Maven","purl":"pkg:maven/org.sonatype.nexus/nexus-repository"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.19.0"}]}],"versions":["3.0.0-03","3.0.1-01","3.0.2-02","3.1.0-04","3.10.0-04","3.11.0-01","3.12.0-01","3.12.1-01","3.13.0-01","3.14.0-04","3.15.0-01","3.15.1-01","3.15.2-01","3.15.3-01","3.16.0-01","3.16.1-02","3.16.2-01","3.17.0-01","3.17.1-01","3.17.2-03","3.18.0-01","3.18.1-01","3.2.0-01","3.2.1-01","3.3.0-01","3.3.1-01","3.3.2-02","3.4.0-02","3.5.0-02","3.5.1-02","3.5.2-01","3.6.0-02","3.6.1-02","3.6.2-01","3.7.0-04","3.7.1-02","3.8.0-02","3.9.0-01"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hmjv-px3j-933c/GHSA-hmjv-px3j-933c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}