ZeroHour

CVE-2020-10199

KEV PoC large

Authenticated Java EL Injection RCE in Sonatype Nexus Repository (before 3.21.2)

CISA: Sonatype Nexus Repository Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
99%p100
Published
()
KEV added
AI analysis

Sonatype Nexus Repository versions before 3.21.2 contain a Java Expression Language (EL) injection flaw (CWE-917) in which attacker-supplied EL expressions are evaluated by the server, the first of two related injection issues fixed by this release. Because the CVSS vector requires only low privileges (an authenticated user) over the network with no user interaction, a low-privileged authenticated user can trigger the flaw by submitting crafted input containing EL expressions that the repository server evaluates. Successful exploitation yields remote code execution on the Nexus host with high impact on confidentiality, integrity, and availability, effectively letting the attacker run commands as the Nexus service account and access stored artifacts and configuration. Any organization running Nexus Repository 3 prior to 3.21.2 is affected, particularly instances exposed to the internet or accessible to untrusted users. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries an EPSS probability of 99.1%, and a public proof-of-concept for Nexus 3.21.1 is available.

What to do: Upgrade Nexus Repository to version 3.21.2 or later per vendor instructions; this release also fixes the companion (second) EL injection issue. If patching is delayed, restrict access to the Nexus UI and REST APIs to trusted authenticated accounts only, remove anonymous/untrusted access, and place internet-exposed instances behind a VPN or firewall. Hunt for signs of exploitation on instances that ran vulnerable versions, including unexpected processes or commands run as the Nexus service account.

Affected
Sonatype Nexus RepositoryAll versions before 3.21.2 (Nexus Repository 3.x prior to 3.21.2)
Estimated exposure
largetens of thousands of internet-exposed Nexus Repository instances (order of magnitude ~10^4), plus an unknown but substantial number of internal-only deployments — Public internet-wide scans have historically indexed tens of thousands of Nexus Repository servers, and the product's deployment pattern of one centralized artifact repository per development organization keeps the exposed count in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

CISA Known Exploited Vulnerability
Affected
Sonatype Nexus Repository
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sonatype
Products
nexus
Weakness
CWE-917
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.