Medium severity5.4NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026
CVE-2021-37152
CVE-2021-37152
Description
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:*range: >=3.0.0,<3.33.0
- (no CPE)range: <3.33.0
- Sonatype/Nexus Repository Managerdescription
Patches
Vulnerability mechanics
References
2- support.sonatype.comnvdVendor Advisory
- support.sonatype.com/hc/en-us/articles/4404115639827nvdVendor Advisory
News mentions
0No linked articles in our index yet.