Junglewise Threat Intelligence

CVE-2020-10199: Nexus Repository Manager 3 - Remote Code Execution

CVE-2020-10199 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-04-14

Technologies: Sonatype Nexus Repository. Vendors: Maven, Sonatype.

Executive brief

Sonatype Nexus Repository is vulnerable to Java Expression Language (EL) injection, which allows an authenticated remote attacker to execute arbitrary code on the server. The vulnerability exists in versions prior to 3.21.2.

Affected products

  • Sonatype Nexus Repository before 3.21.2

Timeline

  • 2020-04-01: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-04-01: patched: Fixed in version 3.21.2
  • exploited: Reported as exploited in the wild and listed in CISA KEV.

Related threats