VYPR
Unrated severityNVD Advisory· Published Aug 10, 2021· Updated Aug 4, 2024

CVE-2021-37152

CVE-2021-37152

Description

Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated XSS in Sonatype Nexus Repository Manager 3 before 3.33.0 allows attackers to inject malicious HTML via repository file uploads.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in Sonatype Nexus Repository Manager 3 versions prior to 3.33.0. An authenticated attacker with the ability to add HTML files to a repository can inject malicious scripts. The affected versions include all 3.x releases before 3.33.0.

Exploitation

To exploit, the attacker must have valid authentication and the permission to upload HTML files to a repository. The attacker uploads a crafted HTML file containing malicious JavaScript. When other users access that file or are redirected to Nexus Repository Manager pages that render the file, the script executes in the context of the victim's session.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the Nexus Repository Manager application. This can lead to session hijacking, unauthorized actions, and data theft, effectively compromising the integrity and confidentiality of the repository management system.

Mitigation

The issue is fixed in Sonatype Nexus Repository Manager version 3.33.0. Users should upgrade to this version or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.