VYPR
High severityCISA KEVNVD Advisory· Published Apr 1, 2020· Updated Oct 21, 2025

CVE-2020-10199

CVE-2020-10199

Description

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.sonatype.nexus:nexus-extdirectMaven
< 3.21.23.21.2

Affected products

1
  • Sonatype/Nexus Repositorydescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.