LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7238: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 10, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7238 to its Known Exploited Vulnerabilities catalog on Dec 10, 2021, with a federal patch deadline of Jun 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

CVE-2019-7238 is an incorrect access control vulnerability in Sonatype Nexus Repository Manager versions before 3.15.0. Successful exploitation can lead to remote code execution on the affected host. For teams that rely on Nexus as an internal artifact and package repository, this matters because a compromised instance can expose build pipelines, credentials, and downstream systems that pull packages from it. Confirm exact fixed versions and deployment details against the vendor advisory.

How it works

The flaw is described as incorrect access control. In products of this class, that typically means an authentication or authorization check is missing, incomplete, or bypassable on a sensitive function. An unauthenticated or insufficiently privileged remote attacker can reach functionality that should be restricted and use it to execute code in the context of the Nexus process.

Public detail on the precise request path, parameters, or bypass technique is limited in the material provided here. Do not assume a particular exploit chain; treat any unauthenticated or low-privilege interaction with the management or repository API surface as potentially dangerous until the instance is confirmed patched. Remote code execution on a repository manager often yields the service account’s privileges, access to stored artifacts and credentials, and a foothold for lateral movement into CI/CD infrastructure.

Am I affected? How to find it in your systems

Sonatype Nexus Repository Manager is commonly deployed as an internal Maven, npm, Docker, or general binary repository, often on Linux servers, containers, or VMs reachable from developer networks and build agents. Inventory steps:

For signs of exploitation, review application and access logs for unusual unauthenticated or privileged API calls, unexpected process spawns under the Nexus user, new or modified repository content, and outbound connections from the Nexus host that do not match normal mirror or proxy behavior. Correlate with host EDR/telemetry for shell or scripting activity originating from the Java/service process. Absence of clear indicators does not prove the system was not targeted; limited public exploit detail means log signatures may be incomplete.

How to remediate

Patch first. Apply updates per the vendor’s instructions so that Nexus Repository Manager is no longer on a version before 3.15.0. Validate the installed version after upgrade and restart services only as the vendor documents. CISA’s required action is to apply updates per vendor instructions; treat that as the primary fix.

After patching, harden in line with this weakness class:

Re-check configuration against the current vendor security guidance after the upgrade.

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

These controls do not replace the patch; they only buy time. Schedule the upgrade promptly and confirm completion against the vendor advisory.

If your data may have been exposed

Actively exploited remote code execution flaws on repository managers can lead to theft of artifacts, credentials, and pipeline secrets, and to broader environment compromise. If you have reason to believe an instance was reachable and unpatched during a period of known activity, treat it as a potential incident: isolate, preserve logs, rotate secrets, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then prioritize password and token resets accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonatype · Nexus Repository Manager
Added to CISA KEVDec 10, 2021
Federal patch deadlineJun 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities