Sonatype Inc.

First CVE: Mar 21, 2024Active for: 2 years
29
CVEs Published
More CVEs Published than 48% of tracked CNAs
9.7
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Sonatype Inc. as a CNA, 13.8% affect products that Sonatype Inc. develops as a vendor.

13.8%
86.2%
Self-reported: 4Third-party: 25

Of all the CVEs published that affect products developed by Sonatype Inc., 8.7% are self-published by Sonatype Inc. as a CNA.

91.3%
Self-published: 4Published by other CNAs: 42

Trends Over Time

The number and severity of CVEs published by Sonatype Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2024
2 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Sonatype Inc. as a CNA, regardless of affected vendor or product.

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
May 16, 20247.555NOYES
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targ
Jul 14, 20268.735NONO
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
Nov 14, 20247.133NOYES
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arb
Jul 14, 20268.232NONO
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to exec
Apr 8, 20269.432NONO
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Nov 28, 20258.831NONO
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in
Jun 16, 20268.630NONO
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorize
Apr 15, 20269.230NONO
Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data struct
Dec 26, 20259.330NONO
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
Jun 11, 20267.528NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA29 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (3.4%)
Network28 (96.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (79.3%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (27.6%)
High6 (20.7%)
None15 (51.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.9% of CVEs· 94th percentile
ExploitDB
1 CVE
3.4% of CVEs· 92nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Sonatype Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Sonatype Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs