PT-2025-41292 · Sonatype · Sonatype Nexus Repository

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-9868

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository versions 2.0 through 2.15.2
Description A Server-Side Request Forgery (SSRF) exists in the Remote Browser Plugin. This allows unauthenticated remote attackers to extract proxy repository credentials via crafted HTTP requests. The issue affects the handling of HTTP requests, potentially enabling unauthorized access to sensitive data.
Recommendations Update Sonatype Nexus Repository to a version later than 2.15.2.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9868

Affected Products

Sonatype Nexus Repository