CVE-2020-11753: High severity sonatype nexus repository 3 vulnerability
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-11753?
CVE-2020-11753 is a vulnerability in Sonatype Nexus Repository Manager that allows a user with appropriate privileges to create, modify, and execute scripting tasks without using the UI or API.
What is the severity of CVE-2020-11753?
CVE-2020-11753 has a severity rating of 8.8 (high).
How does CVE-2020-11753 affect Sonatype Nexus Repository Manager?
CVE-2020-11753 affects Sonatype Nexus Repository Manager versions 3.21.1 and 3.22.0.
Is scripting disabled by default in Sonatype Nexus Repository Manager 3.22.0?
Yes, scripting is disabled by default in Sonatype Nexus Repository Manager version 3.22.0.
How can I fix CVE-2020-11753?
To fix CVE-2020-11753, upgrade to a version of Sonatype Nexus Repository Manager that is not affected by this vulnerability.