{"id":"GHSA-g5m7-57ph-j6p8","summary":"OS Command Injection in Nexus Yum Repository Plugin","details":"The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.","aliases":["CVE-2019-5475"],"modified":"2023-11-01T04:51:00.115100Z","published":"2019-09-11T23:04:57Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-09-04T14:40:16Z","nvd_published_at":"2019-09-03T20:15:00Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5475"},{"type":"WEB","url":"https://hackerone.com/reports/654888"}],"affected":[{"package":{"name":"org.sonatype.nexus.plugins:nexus-yum-repository-plugin","ecosystem":"Maven","purl":"pkg:maven/org.sonatype.nexus.plugins/nexus-yum-repository-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.14.14"}]}],"versions":["2.10.0-01","2.10.0-02","2.11.0-01","2.11.0-02","2.11.1-01","2.11.2-01","2.11.2-03","2.11.2-04","2.11.2-06","2.11.3-01","2.11.4-01","2.12.0-01","2.12.1-01","2.13.0-01","2.14.0-01","2.14.1-01","2.14.10-01","2.14.11-01","2.14.12-02","2.14.13-01","2.14.2-01","2.14.3-02","2.14.4-01","2.14.4-03","2.14.5-02","2.14.6-02","2.14.7-01","2.14.8-01","2.14.9-01","2.7.0-01","2.7.0-02","2.7.0-03","2.7.0-04","2.7.0-05","2.7.0-06","2.7.0-m2","2.7.0-m3","2.7.0-m4","2.7.1-01","2.7.2-01","2.7.2-02","2.7.2-03","2.8.0-01","2.8.0-05","2.8.1-01","2.9.0-01","2.9.0-04","2.9.1-01","2.9.1-02","2.9.2-01"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/09/GHSA-g5m7-57ph-j6p8/GHSA-g5m7-57ph-j6p8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}