CVE-2020-10199

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Basic Information

CVE State
PUBLISHED
Reserved Date
March 06, 2020
Published Date
April 01, 2020
Last Updated
October 21, 2025
Vendor
n/a
Product
n/a
Description
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Tags
java cisa nuclei_scanner metasploit

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

9.0

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2021-11-03 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

nexus_repo_manager_el_injection

Type: metasploit • Created: Unknown

Metasploit module for CVE-2020-10199

aleenzz/CVE-2020-10199

Type: github • Created: 2020-05-15 06:12:51 UTC • Stars: 31

CVE-2020-10199 回显版本

zhzyker/CVE-2020-10199_POC-EXP

Type: github • Created: 2020-04-16 09:40:15 UTC • Stars: 44

CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)

magicming200/CVE-2020-10199_CVE-2020-10204

Type: github • Created: 2020-04-08 11:08:35 UTC • Stars: 25

CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.

jas502n/CVE-2020-10199

Type: github • Created: 2020-04-08 07:36:30 UTC • Stars: 35

CVE-2020-10199、CVE-2020-10204、CVE-2020-11444

wsfengfan/CVE-2020-10199-10204

Type: github • Created: 2020-04-07 13:23:12 UTC • Stars: 19

CVE-2020-10199 CVE-2020-10204 Python POC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit