CVE-2021-37152
Description
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated XSS in Sonatype Nexus Repository Manager 3 before 3.33.0 allows attackers to inject malicious HTML via repository file uploads.
Vulnerability
Multiple cross-site scripting (XSS) vulnerabilities exist in Sonatype Nexus Repository Manager 3 versions prior to 3.33.0. An authenticated attacker with the ability to add HTML files to a repository can inject malicious scripts. The affected versions include all 3.x releases before 3.33.0.
Exploitation
To exploit, the attacker must have valid authentication and the permission to upload HTML files to a repository. The attacker uploads a crafted HTML file containing malicious JavaScript. When other users access that file or are redirected to Nexus Repository Manager pages that render the file, the script executes in the context of the victim's session.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the Nexus Repository Manager application. This can lead to session hijacking, unauthorized actions, and data theft, effectively compromising the integrity and confidentiality of the repository management system.
Mitigation
The issue is fixed in Sonatype Nexus Repository Manager version 3.33.0. Users should upgrade to this version or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Sonatype/Nexus Repository Managerdescription
- Range: <3.33.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.sonatype.commitrex_refsource_MISC
- support.sonatype.com/hc/en-us/articles/4404115639827mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.