Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
https://support.sonatype.com/entries/37828023-Nexus-Security-Vulnerability
https://sonatype.zendesk.com/entries/37551958-Configuring-Xstream-Whitelist