CVE-2019-5475
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data,...
- Published
- Sep 3, 2019
- Updated
- Aug 4, 2024
- Assigning CNA
- hackerone
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:CModerate · next 30 days
- Percentile
- 97.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Sources
3CVE-2019-5475 靶场: RCE 命令注入漏洞
Exploit payload for CVE-2019-5475 in Nexus Repository Manager, enabling remote code execution via crafted Yum capability configuration.
- CVE-2019-5475-EXPExploit
CVE-2019-5475-EXP 【Nexus Repository Manager 2.x远程命令执行漏洞】
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.