News and Notes from the Makers of Nexus | Sonatype Blog | Elisa Velarde

[Sonatype Intelligence Insights: Sonatype - 2020-0003 - npm Malicious Package 1337qq-js](/content/blog/sonatype-2020-0003-npm-malicious-package-1337qq-js "Internal link to Sonatype Intelligence Insights: Sonatype - 2020-0003 - npm Malicious Package 1337qq-js resource"/index.html)

Read More

[Sonatype Intelligence Insights: CVE-2018-5382 Bouncycastle Information Exposure](/content/blog/cve-2018-2018-5382-bouncycastle-information-exposure "Internal link to Sonatype Intelligence Insights: CVE-2018-5382 Bouncycastle Information Exposure resource"/index.html)

Read More

[Sonatype Intelligence Insights: CVE-2018-16487 Lodash RCE + 'prototype' Pollution](/content/blog/cve-2018-16487-lodash-rce-prototype-pollution "Internal link to Sonatype Intelligence Insights: CVE-2018-16487 Lodash RCE + 'prototype' Pollution resource"/index.html)

Read More

[Sonatype Intelligence Insights Sonatype-2017-0312: jackson-databind](/content/blog/jackson-databind-the-end-of-the-blacklist "Internal link to Sonatype Intelligence Insights Sonatype-2017-0312: jackson-databind resource"/index.html)

Read More

Sonatype Intelligence Insights CVE-2019-15753: OpenStack (os-vif), Denial of Service & Information Exposure

Read More

[Sonatype Intelligence Insights: Sonatype-2018-0413, flatmap-stream's Back, Back Again](/content/blog/nexus-intelligence-insights-sonatype-2018-0413 "Internal link to Sonatype Intelligence Insights: Sonatype-2018-0413, flatmap-stream's Back, Back Again resource"/index.html)

Read More

[Sonatype Intelligence Insights: CVE-2019-13354: 'strong_password' Embedded Malicious Code, RubyGems](/content/blog/cve-2019-13354-strong-password "Internal link to Sonatype Intelligence Insights: CVE-2019-13354: 'strong_password' Embedded Malicious Code, RubyGems resource"/index.html)

Read More

Sonatype Intelligence Insights: CVE-2018-1109-Braces Regular Expression Denial of Service (ReDoS) Attack

Read More

[Sonatype Intelligence Insights - CVE-2018-14721 - jackson-databind Remote Code Execution](/content/blog/jackson-databind-remote-code-execution "Internal link to Sonatype Intelligence Insights - CVE-2018-14721 - jackson-databind Remote Code Execution resource"/index.html)

Read More

[Sonatype Intelligence Insights: CVE-2019-0232 - Apache Tomcat CGI Servlet remote code execution](/content/blog/nexus-intelligence-insights-cve-2019-0232-apache-tomcat-cgi-servlet-remote-code-execution "Internal link to Sonatype Intelligence Insights: CVE-2019-0232 - Apache Tomcat CGI Servlet remote code execution resource"/index.html)

Read More

[Lessons Learned From the Bootstrap-sass Hack](/content/blog/corrupting-the-software-supply-chain-lessons-from-the-bootstrap-sass-hack "Internal link to Lessons Learned From the Bootstrap-sass Hack resource"/index.html)

Read More

[Sonatype Intelligence Insights: CVE-2014-3483 - SQL Injection in PostgreSQL Adapter for Active Record against 'range' Data Type](/content/blog/nexus-intelligence-insights-cve-2014-3483 "Internal link to Sonatype Intelligence Insights: CVE-2014-3483 - SQL Injection in PostgreSQL Adapter for Active Record against 'range' Data Type resource"/index.html)

Read More