Executive brief
Sonatype Nexus Repository is vulnerable to Java Expression Language (EL) injection, which allows an authenticated remote attacker to execute arbitrary code on the server. The vulnerability exists in versions prior to 3.21.2.
Affected products
- Sonatype Nexus Repository before 3.21.2
Timeline
- 2020-04-01: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-04-01: patched: Fixed in version 3.21.2
- exploited: Reported as exploited in the wild and listed in CISA KEV.