{"id":"GHSA-g2f6-v5qh-h2mq","summary":"Nexus Repository Manager 3 - Remote Code Execution ","details":"Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).","aliases":["CVE-2020-10199"],"modified":"2025-10-22T19:17:19.496144Z","published":"2020-04-14T15:27:05Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-04-14T15:26:13Z","nvd_published_at":"2020-04-01T19:15:00Z","cwe_ids":["CWE-917"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10199"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/917.html"},{"type":"PACKAGE","url":"https://github.com/sonatype/nexus-public"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2020-015-nxrm-sonatype"},{"type":"WEB","url":"https://support.sonatype.com/hc/en-us/articles/360044882533"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10199"},{"type":"WEB","url":"http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html"}],"affected":[{"package":{"name":"org.sonatype.nexus:nexus-extdirect","ecosystem":"Maven","purl":"pkg:maven/org.sonatype.nexus/nexus-extdirect"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.2"}]}],"versions":["3.0.0-03","3.0.1-01","3.0.2-02","3.1.0-04","3.10.0-04","3.11.0-01","3.12.0-01","3.12.1-01","3.13.0-01","3.14.0-04","3.15.0-01","3.15.1-01","3.15.2-01","3.15.3-01","3.16.0-01","3.16.1-02","3.16.2-01","3.17.0-01","3.17.1-01","3.17.2-03","3.18.0-01","3.18.1-01","3.19.0-01","3.19.1-01","3.2.0-01","3.2.1-01","3.20.0-02","3.20.0-04","3.20.1-01","3.20.2-01","3.20.3-01","3.21.0-01","3.21.0-02","3.21.0-05","3.21.1-01","3.3.0-01","3.3.1-01","3.3.2-02","3.4.0-02","3.5.0-02","3.5.1-02","3.5.2-01","3.6.0-02","3.6.1-02","3.6.2-01","3.7.0-04","3.7.1-02","3.8.0-02","3.9.0-01"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-g2f6-v5qh-h2mq/GHSA-g2f6-v5qh-h2mq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H"}]}