CVE-2021-37152: XSS
Published Aug 10, 2021
·Updated
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Affected Software
1 affected component
Sonatype Nexus Repository Manager>=3.0.0<3.33.0
Event History
Aug 10, 2021
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37152?
CVE-2021-37152 refers to multiple XSS issues in Sonatype Nexus Repository Manager 3 before version 3.33.0.
2
How severe is CVE-2021-37152?
The severity of CVE-2021-37152 is rated as medium, with a CVSS score of 5.4.
3
What software is affected by CVE-2021-37152?
Sonatype Nexus Repository Manager versions between 3.0.0 and 3.33.0 are affected by CVE-2021-37152.
4
How can an attacker exploit CVE-2021-37152?
An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.