The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.sonatype.nexus.plugins:nexus-yum-repository-plugin(Maven) | 0 | 2.14.14 | N/A |
CVSS Metrics