Sonatype Nexus Repository Manager 3 - Remote Code Execution
CVE-2020-10204
Verified
Description
Sonatype Nexus Repository Manager 3 up to and including 3.21.1 is vulnerable to Expression Language injection. An attacker authenticated with an administrative account can inject an EL expression into the user "roles" field of the coreui_User update endpoint, leading to remote code execution. This is a bypass of the fix for CVE-2018-16621.
Severity
High
CVSS Score
7.2
Exploit Probability
38%
Affected Product
nexus
Published Date
August 16, 2026
Template Author
mmadersbacher
CVE-2020-10204.yaml
7.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2020-10204
CWE ID:
cwe-20
Remediation Steps
Upgrade to Sonatype Nexus Repository Manager 3.21.2 or later.