CVE-2020-10199

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Basic Information

CVE State
PUBLISHED
Reserved Date
March 06, 2020
Published Date
April 01, 2020
Last Updated
February 04, 2025
Vendor
n/a
Product
n/a
Description
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

CVSS Scores

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2020-04-07 13:23:12 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

nexus_repo_manager_el_injection

Type: metasploit • Created: Unknown

Metasploit module for CVE-2020-10199

aleenzz/CVE-2020-10199

Type: github • Created: 2020-05-15 06:12:51 UTC • Stars: 31

CVE-2020-10199 回显版本

zhzyker/CVE-2020-10199_POC-EXP

Type: github • Created: 2020-04-16 09:40:15 UTC • Stars: 44

CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)

magicming200/CVE-2020-10199_CVE-2020-10204

Type: github • Created: 2020-04-08 11:08:35 UTC • Stars: 25

CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.

jas502n/CVE-2020-10199

Type: github • Created: 2020-04-08 07:36:30 UTC • Stars: 35

CVE-2020-10199、CVE-2020-10204、CVE-2020-11444

wsfengfan/CVE-2020-10199-10204

Type: github • Created: 2020-04-07 13:23:12 UTC • Stars: 19

CVE-2020-10199 CVE-2020-10204 Python POC