/Vulnerability Library

Sonatype Nexus Repository Manager 3 - Remote Code Execution

CVE-2020-10204
Verified

Description

Sonatype Nexus Repository Manager 3 up to and including 3.21.1 is vulnerable to Expression Language injection. An attacker authenticated with an administrative account can inject an EL expression into the user "roles" field of the coreui_User update endpoint, leading to remote code execution. This is a bypass of the fix for CVE-2018-16621.

Severity

High

CVSS Score

7.2

Exploit Probability

38%

Affected Product

nexus

Published Date

August 16, 2026

Template Author

mmadersbacher

CVE-2020-10204.yaml
7.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2020-10204
CWE ID:
cwe-20

References

https://github.com/vulhub/vulhub/tree/master/nexus/CVE-2020-10204https://nvd.nist.gov/vuln/detail/CVE-2020-10204

Remediation Steps

Upgrade to Sonatype Nexus Repository Manager 3.21.2 or later.