CVE-2020-10199: Sonatype Nexus Repository Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 99.1% chance of exploitation in the next 30 days.

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Affected products

  • Sonatype Nexus: before 3.21.2 (fixed in 3.21.2)

Published 2020-04-01. Last modified 2026-06-17.