GHSA-g2f6-v5qh-h2mq
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2020-10199, https://cwe.mitre.org/data/definitions/917.html, https://github.com/sonatype/nexus-public, https://securitylab.github.com/advisories/GHSL-2020-015-nxrm-sonatype, https://support.sonatype.com/hc/en-us/articles/360044882533, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10199, http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html, http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html
