Sonatype Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Sonatype products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

2

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Sonatype KEVs Added by Year

Loading...

2 Sonatype KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-10199

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Confirmed In CISA 03 Nov 2021
CVE-2019-7238

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Confirmed In CISA 10 Dec 2021

Common Vulnerability Classes (CWE)

  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology