GHSA-g5m7-57ph-j6p8
GitHub Security Advisory
OS Command Injection in Nexus Yum Repository Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Affected Packages
Maven
org.sonatype.nexus.plugins:nexus-yum-repository-plugin
Affected versions:
0
(fixed in 2.14.14)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: October 1, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.