CVE-2020-10199

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Basic Information

CVE State
PUBLISHED
Reserved Date
March 06, 2020
Published Date
April 01, 2020
Last Updated
July 30, 2025
Vendor
Sonatype
Product
Nexus Repository
Description
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Tags
cisa nuclei_scanner metasploit_scanner

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

9.0

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2020-04-07 13:23:12 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

nexus_repo_manager_el_injection

Type: metasploit • Created: Unknown

Metasploit module for CVE-2020-10199

aleenzz/CVE-2020-10199

Type: github • Created: 2020-05-15 06:12:51 UTC • Stars: 31

CVE-2020-10199 回显版本

zhzyker/CVE-2020-10199_POC-EXP

Type: github • Created: 2020-04-16 09:40:15 UTC • Stars: 44

CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)

magicming200/CVE-2020-10199_CVE-2020-10204

Type: github • Created: 2020-04-08 11:08:35 UTC • Stars: 25

CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.

jas502n/CVE-2020-10199

Type: github • Created: 2020-04-08 07:36:30 UTC • Stars: 35

CVE-2020-10199、CVE-2020-10204、CVE-2020-11444

wsfengfan/CVE-2020-10199-10204

Type: github • Created: 2020-04-07 13:23:12 UTC • Stars: 19

CVE-2020-10199 CVE-2020-10204 Python POC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit