vendor:
Nexus Repository Manager
by:
1F98D
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Nexus Repository Manager
Affected Version From: 3.21.1
Affected Version To: 3.21.1
Patch Exists: YES
Related CWE: CVE-2020-10199
CPE: a:sonatype:nexus_repository_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2020
Sonatype Nexus 3.21.1 – Remote Code Execution (Authenticated)
Nexus Repository Manager 3 versions 3.21.1 and below are vulnerable to Java EL injection which allows a low privilege user to remotely execute code on the target server.
Mitigation:
Upgrade to Nexus Repository Manager 3.21.2 or later.