CVE-2020-11753
גבוהה 8.8
תיאור (מקור, אנגלית)
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-26/9/2026
- CWE
- CWE-863
מוצרים מושפעים
sonatype: nexus repository manager
קישורים
- https://support.sonatype.com/hc/en-us/articles/360046233714 PatchVendor Advisory
- https://support.sonatype.com/hc/en-us/articles/360046233714 PatchVendor Advisory
- https://cwe.mitre.org/data/definitions/284.html Third Party Advisory
- https://cwe.mitre.org/data/definitions/284.html Third Party Advisory