The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
https://github.com/EXP-Docs/CVE-2019-15588
https://github.com/lyy289065406/CVE-2019-5475
https://github.com/EXP-Docs/CVE-2019-5475
https://github.com/rabbitmask/CVE-2019-5475-EXP