CVE-2018-16621
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
- Affected products
- Nexus Repository Manager
- Sonatype Nexus Repository Manager
- < 3.14.0
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 5.1% (92th percentile)
- Weakness
- CWE-917
- NVD status
- Modified
- Published
- 2018-11-15
CVE-2018-16621 at NVD
2 known exploits for CVE-2018-16621
Proof-of-concept code and exploit modules indexed by Sploitus