CVE-2020-10199
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
- Affected products
- Nexus Repository Manager, Sonatype Nexus Repository
- Sonatype Nexus
- < 3.21.2
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 99.1% (100th percentile)
- Weakness
- CWE-917
- NVD status
- Analyzed
- Published
- 2020-04-01
CVE-2020-10199 at NVD
16 known exploits for CVE-2020-10199
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-10199_POC-EXP
CVE-2020-10199_CVE-2020-10204
CVE-2020-10199
CVE-2020-10199
CVE-2020-10199-10204
CVE-2020-10199
CVE-2020-10199-Nexus-3.21.01
Sonatype Nexus 3.21.1 Remote Code Execution
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
Exploit for Expression Language Injection in Sonatype Nexus
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
Nexus Repository Manager 3.21.1-01 Remote Code Execution
Exploit for Expression Language Injection in Sonatype Nexus
Nexus Repository Manager 3.21.1-01 Remote Code Execution Exploit
Exploit for Expression Language Injection in Sonatype Nexus
Nexus Repository Manager Java EL Injection RCE