High severity8.8CISA KEVNVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026
CVE-2020-10199
CVE-2020-10199
Description
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.sonatype.nexus:nexus-extdirectMaven | < 3.21.2 | 3.21.2 |
Affected products
3- Sonatype/Nexus Repositorydescription
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.htmlnvdPatchThird Party AdvisoryVDB EntryWEB
- support.sonatype.com/hc/en-us/articles/360044882533nvdPatchVendor AdvisoryWEB
- packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- cwe.mitre.org/data/definitions/917.htmlnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-g2f6-v5qh-h2mqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-10199ghsaADVISORY
- securitylab.github.com/advisories/GHSL-2020-015-nxrm-sonatypeghsaADVISORY
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
0No linked articles in our index yet.