CVE-2020-10204

HIGH8.8EPSS 55.8%

Remote Code Execution - JavaEL Injection (low privileged accounts) in Nexus Repository Manager

Published: 4/14/2020Modified: 11/8/2023
Also known as:GHSA-8h56-v53h-5hhj

Description

Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (5)