Code Injection in Nexus Repository Manager - CVE-2020-10199
Published: April 2, 2020 / Updated: June 14, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote authenticated attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2020-10199
Links to Public Exploits and PoC-codes
- Exploit #9107 - CVE-2020-10199-Nexus-3.21.01 (Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)) (June 14, 2023)
- Exploit #5725 - Nexus Repository Manager - Java EL Injection RCE (Metasploit) (June 17, 2021)
- Exploit #5621 - Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated) (June 17, 2021)
- Exploit #5036 - poc (CVE-2020-14882) (January 18, 2021)
- Exploit #2908 - CVE-2020-10199-10204 (CVE-2020-10199 CVE-2020-10204 Python POC) (June 3, 2020)
- Exploit #2915 - CVE-2020-10199 (CVE-2020-10199、CVE-2020-10204、CVE-2020-11444) (June 3, 2020)
- Exploit #2921 - CVE-2020-10199_CVE-2020-10204 (CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.) (June 3, 2020)
- Exploit #2972 - CVE-2020-10199 (CVE-2020-10199 回显版本) (June 3, 2020)
- Exploit #3000 - CVE-2020-10199_POC-EXP (CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)) (June 3, 2020)
- Exploit #2581 - Nexus Repository Manager Java EL Injection RCE (April 16, 2020)