CVE-2020-15871High· 8.8▾ TwilightSonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
nexus_repository_manager < 3.25.1Upgrade past the affected range:
nexus_repository_manager 3.25.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15870Medium· 6.1Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
CVE-2020-15869Medium· 5.4Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
CVE-2021-40143High· 8.2Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection
CVE-2021-29158Medium· 4.9Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
CVE-2020-11753High· 8.8An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0
CVE-2026-7494Medium· 5.0Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint