ZeroHour

CVE-2019-7238

KEVlarge

Incorrect Access Control in Sonatype Nexus Repository Manager before 3.15.0

CISA: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
77%p100
Published
()
KEV added
AI analysis

CVE-2019-7238 is an incorrect access control flaw in Sonatype Nexus Repository Manager versions before 3.15.0 that is triggerable over the network by unauthenticated attackers with no user interaction, earning a critical CVSS 3.1 score of 9.8 with high impact on confidentiality, integrity, and availability. Any attacker who can reach a vulnerable instance can gain high-impact access to the repository server, consistent with full compromise of the system and the software artifacts it hosts and serves. All deployments running Nexus Repository Manager releases prior to 3.15.0 are affected, whether exposed to the internet or hosted internally as part of build and CI/CD pipelines. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities Catalog on 2021-12-10 (ransomware use unknown), EPSS assigns a 77.1% probability of exploitation within 30 days, no public PoC is known, and the related WatchBog Linux botnet headlines are consistent with the cryptomining campaigns that targeted Nexus Repository Manager deployments in this period.

What to do: Upgrade all Nexus Repository Manager deployments to version 3.15.0 or later per Sonatype and CISA instructions, and inventory any 3.x instances still running older releases, prioritizing internet-facing ones. Restrict network access to the Nexus service to trusted networks and users, and check instances for signs of compromise such as unexpected cryptomining processes or outbound connections to Pastebin, consistent with the botnet campaigns referenced in related reporting.

Affected
sonatype nexus repository managerall versions before 3.15.0
Estimated exposure
large≈10,000–100,000 internet-exposed Nexus Repository Manager instances, with a likely larger total installed base including internal-only deployments — Nexus Repository Manager is a dominant enterprise artifact repository for Maven/npm/PyPI ecosystems, and public internet scans (e.g., Shodan-style indexes) have historically shown tens of thousands of internet-facing Nexus instances,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

CISA Known Exploited Vulnerability
Affected
Sonatype Nexus Repository Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sonatype
Products
nexus repository manager
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news