CVE-2020-10199

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

  • Published Apr 1, 2020
  • CVSS 8.8 high
  • 99.1% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it
  • A fix is available

CVE-2020-10199 at the National Vulnerability Database