HIGH8.8
GHSA-8h56-v53h-5hhj
Remote Code Execution - JavaEL Injection (low privileged accounts) in Nexus Repository Manager
Quick fix
GHSA-8h56-v53h-5hhj — org.sonatype.nexus:nexus-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.21.2</version> for org.sonatype.nexus:nexus-coreDetails
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.sonatype.nexus:nexus-core
Introduced in:
0Fixed in: 3.21.2Fix
# pom.xml: bump <version>3.21.2</version> for org.sonatype.nexus:nexus-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-10204[ADVISORY]
- https://securitylab.github.com/advisories/GHSL-2020-011-nxrm-sonatype[ADVISORY]
- https://securitylab.github.com/advisories/GHSL-2020-012-nxrm-sonatype[ADVISORY]
- https://support.sonatype.com/hc/en-us/articles/360044356194[WEB]
- https://support.sonatype.com/hc/en-us/articles/360044882533[WEB]