PT-2026-31544 · Sonatype · Sonatype Nexus Repository
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Sonatype Nexus Repository versions 3.22.1 through 3.90.2
Description
A flaw in the task management component allows an authenticated attacker with task creation permissions to execute arbitrary code. This is achieved through task property injection, which bypasses the
nexus.scripts.allowCreation security control.Recommendations
Update to a version later than 3.90.2.
As a temporary mitigation, restrict task creation permissions to trusted users only.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonatype Nexus Repository