{"id":"CVE-2020-11753","title":"An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0","summary":"An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"sonatype","product":"nexus_repository_manager","affected":["nexus_repository_manager = 3.21.1","nexus_repository_manager = 3.22.0"],"published":"2020-04-20","updated":"2026-09-22","sourceUpdated":"2026-09-22T18:13:24.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-11753","references":[{"url":"https://cwe.mitre.org/data/definitions/284.html","label":"cve@mitre.org"},{"url":"https://support.sonatype.com/hc/en-us/articles/360046233714","label":"cve@mitre.org"},{"url":"https://cwe.mitre.org/data/definitions/284.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.sonatype.com/hc/en-us/articles/360046233714","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01715,"epssPercentile":0.76402,"ingestedAt":"2026-09-22T19:09:09.955Z","slug":"CVE-2020-11753","body":"## Overview\n\nAn issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).\n\n## Affected\n\n- `nexus_repository_manager = 3.21.1`\n- `nexus_repository_manager = 3.22.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}