{"id":"UBUNTU-CVE-2014-0792","details":"Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.","modified":"2025-08-01T04:49:23Z","published":"2014-01-17T20:55:00Z","withdrawn":"2025-08-01T19:34:26Z","upstream":["CVE-2014-0792"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0792"},{"type":"REPORT","url":"https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability"},{"type":"REPORT","url":"http://www.sonatype.org/advisories/archive/2014-01-13-Nexus"},{"type":"REPORT","url":"https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2014-0792"}],"affected":[{"package":{"name":"maven-indexer","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/maven-indexer@5.1.1-4?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.1.1-1","5.1.1-2","5.1.1-3","5.1.1-4"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0792.json"}},{"package":{"name":"maven-indexer","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/maven-indexer@5.1.1-6?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.1.1-5","5.1.1-6"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0792.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}