CVE-2019-7238
KEVlargeIncorrect Access Control in Sonatype Nexus Repository Manager before 3.15.0
CISA: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
CVE-2019-7238 is an incorrect access control flaw in Sonatype Nexus Repository Manager versions before 3.15.0 that is triggerable over the network by unauthenticated attackers with no user interaction, earning a critical CVSS 3.1 score of 9.8 with high impact on confidentiality, integrity, and availability. Any attacker who can reach a vulnerable instance can gain high-impact access to the repository server, consistent with full compromise of the system and the software artifacts it hosts and serves. All deployments running Nexus Repository Manager releases prior to 3.15.0 are affected, whether exposed to the internet or hosted internally as part of build and CI/CD pipelines. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities Catalog on 2021-12-10 (ransomware use unknown), EPSS assigns a 77.1% probability of exploitation within 30 days, no public PoC is known, and the related WatchBog Linux botnet headlines are consistent with the cryptomining campaigns that targeted Nexus Repository Manager deployments in this period.
What to do: Upgrade all Nexus Repository Manager deployments to version 3.15.0 or later per Sonatype and CISA instructions, and inventory any 3.x instances still running older releases, prioritizing internet-facing ones. Restrict network access to the Nexus service to trusted networks and users, and check instances for signs of compromise such as unexpected cryptomining processes or outbound connections to Pastebin, consistent with the botnet campaigns referenced in related reporting.
| sonatype nexus repository manager | all versions before 3.15.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
- Affected
- Sonatype Nexus Repository Manager
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sonatype
- Products
- nexus repository manager
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H