CVE-2014-0792
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
Date published : 2014-01-17
http://www.sonatype.org/advisories/archive/2014-01-13-Nexus
https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist