CVE-2020-10199: Sonatype Nexus Repository Remote Code Execution Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 99.1% chance of exploitation in the next 30 days.
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Affected products
- Sonatype Nexus: before 3.21.2 (fixed in 3.21.2)
Published 2020-04-01. Last modified 2026-06-17.