PT-2025-41292 · Sonatype · Sonatype Nexus Repository
CVE-2025-9868
·
Publicado
2025-10-08
·
Atualizado
2025-10-08
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sonatype Nexus Repository versions 2.0 through 2.15.2
Description
A Server-Side Request Forgery (SSRF) exists in the Remote Browser Plugin. This allows unauthenticated remote attackers to extract proxy repository credentials via crafted HTTP requests. The issue affects the handling of HTTP requests, potentially enabling unauthorized access to sensitive data.
Recommendations
Update Sonatype Nexus Repository to a version later than 2.15.2.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sonatype Nexus Repository