LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-10199: Sonatype Nexus Repository Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-10199 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

CVE-2020-10199 is a remote code execution vulnerability in Sonatype Nexus Repository. CISA describes it as an unspecified flaw that lets an attacker run code on the affected system. For teams that rely on Nexus to host and distribute artifacts, successful exploitation can give an attacker control over the repository host and the software supply chain it serves. Confirm exact impact, versions, and fixes against the vendor advisory.

How it works

The weakness is tracked as CWE-917 (expression language injection). In products of this class, user-controlled input is evaluated by an expression language engine without proper sanitization or sandboxing. An attacker who can reach the vulnerable interface supplies crafted input that the engine interprets as code rather than data. That evaluation can lead to arbitrary command execution in the context of the Nexus process. Public detail on the precise injection point and request format for this CVE is limited; treat any exploit descriptions outside the vendor advisory as unverified and validate them before use in testing or detection.

Because the outcome is remote code execution, a successful attack typically yields the privileges of the Nexus service account. From there an adversary may alter stored artifacts, steal credentials, move laterally, or establish persistence. No ransomware use is documented for this CVE in the supplied facts.

Am I affected? How to find it in your systems

Sonatype Nexus Repository is commonly deployed as an internal or DMZ-facing artifact manager for Maven, npm, Docker, and other package formats. It often runs as a standalone Java service or in containers on build networks, developer workstations, or shared infrastructure.

How to remediate

Patch first. Apply the updates published by Sonatype for Nexus Repository exactly as described in the vendor advisory and in line with CISA’s required action to apply updates per vendor instructions. After upgrading, verify the running version and restart services as required so the fix is active.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities are frequently used to establish footholds that lead to data theft or supply-chain compromise. If you have evidence of exploitation or cannot rule it out, treat the host and any credentials or artifacts it held as potentially compromised: rotate secrets, audit published packages for tampering, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonatype · Nexus Repository
WeaknessCWE-917
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities