Nexus Repository
by Sonatype
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13488 | Med | 0.33 | — | 0.00 | Dec 4, 2025 | Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS)… | ||
| CVE-2024-5083 | Med | 0.33 | — | 0.00 | Nov 14, 2024 | A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. | ||
| CVE-2020-24622 | Med | 0.32 | 4.9 | 0.01 | Aug 25, 2020 | In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. | ||
| CVE-2022-27907 | Med | 0.28 | 4.3 | 0.01 | Mar 30, 2022 | Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF. | ||
| CVE-2021-43961 | Med | 0.28 | 4.3 | 0.01 | Mar 17, 2022 | Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. | ||
| CVE-2026-17597 | Low | 0.18 | 2.7 | 0.00 | Aug 7, 2026 | Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the… | ||
| CVE-2026-17595 | Low | 0.18 | 2.7 | 0.00 | Aug 7, 2026 | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal… |
- risk 0.33cvss —epss 0.00
Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS)…
- risk 0.33cvss —epss 0.00
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
- risk 0.32cvss 4.9epss 0.01
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
- risk 0.28cvss 4.3epss 0.01
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
- risk 0.28cvss 4.3epss 0.01
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
- risk 0.18cvss 2.7epss 0.00
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…
- risk 0.18cvss 2.7epss 0.00
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal…
Page 2 of 2