HIGH8.8
GHSA-g2f6-v5qh-h2mq
Nexus Repository Manager 3 - Remote Code Execution
Quick fix
GHSA-g2f6-v5qh-h2mq — org.sonatype.nexus:nexus-extdirect: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.21.2</version> for org.sonatype.nexus:nexus-extdirectDetails
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.sonatype.nexus:nexus-extdirect
Introduced in:
0Fixed in: 3.21.2Fix
# pom.xml: bump <version>3.21.2</version> for org.sonatype.nexus:nexus-extdirectReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-10199[ADVISORY]
- https://cwe.mitre.org/data/definitions/917.html[WEB]
- https://github.com/sonatype/nexus-public[PACKAGE]
- https://securitylab.github.com/advisories/GHSL-2020-015-nxrm-sonatype[ADVISORY]
- https://support.sonatype.com/hc/en-us/articles/360044882533[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10199[WEB]
- http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html[WEB]
- http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html[WEB]