Back to Database
Status published
Unknown
CVE-2020-10199
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1...
Vulnerability Description
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10199
Credits & Attribution
No credits recorded in the NVD database.
References
- https://support.sonatype.com/hc/en-us/articles/360044882533
- http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html
- https://cwe.mitre.org/data/definitions/917.html
More from sonatype
View All →CVE-2022-27907
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF....
Medium
4.3
CVE-2021-43961
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection....
Medium
4.3
CVE-2021-43293
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote...
Medium
4.3
CVE-2021-42568
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to...
Medium
4.3
CVE-2021-40143
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an...
High
8.2
Affected Vendor
sonatype
View all reports →Affected Software
nexus
Vulnerable Versions:
0
Timeline
Official Publish:
April 1st, 2020
Last Modified:
October 21st, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.