Loading HuntDB...

GHSA-g5m7-57ph-j6p8

GitHub Security Advisory

OS Command Injection in Nexus Yum Repository Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

Affected Packages

Maven org.sonatype.nexus.plugins:nexus-yum-repository-plugin
Affected versions: 0 (fixed in 2.14.14)

Related CVEs

Key Information

GHSA ID
GHSA-g5m7-57ph-j6p8
Published
September 11, 2019 11:04 PM
Last Modified
August 17, 2021 10:25 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.sonatype.nexus.plugins:nexus-yum-repository-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: October 1, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.